PT-2026-97804 · Unknown · Aureus Erp

·

CVE-2026-97062

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Aureus ERP versions prior to 1.6.1
Description The application stores uploaded SVG files on its public disk and serves them from the application origin. This allows authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft these files with script elements that execute within the application's origin when the file URL is opened directly, which can lead to the theft of session cookies and the exfiltration of CSRF (Cross-Site Request Forgery) tokens, a technique used to perform unauthorized actions on behalf of a user.
Recommendations Update Aureus ERP to a version newer than 1.6.0. Restrict the upload of SVG files or sanitize them to remove script elements as a temporary mitigation measure.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97062

Affected Products

Aureus Erp