๐Ÿ” CVE Alert

CVE-2026-4175

LOW 3.5

Aureus ERP Chatter Message content-text-entry.blade.php cross site scripting

CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php of the component Chatter Message Handler. Executing a manipulation of the argument subject/body can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 1.3.0-BETA1 is sufficient to fix this issue. This patch is called 2135ee7efff4090e70050b63015ab5e268760ec8. It is suggested to upgrade the affected component.

CWE CWE-79 CWE-94
Vendor aureus
Product erp
Published Mar 15, 2026
Last Updated Mar 17, 2026
Stay Ahead of the Next One

Get instant alerts for aureus erp

Be the first to know when new low vulnerabilities affecting aureus erp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Aureus / ERP
1.3.0-BETA2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.351083 vuldb.com: https://vuldb.com/?ctiid.351083 vuldb.com: https://vuldb.com/?submit.769827 github.com: https://github.com/aureuserp/aureuserp/pull/939 github.com: https://github.com/aureuserp/aureuserp/commit/2135ee7efff4090e70050b63015ab5e268760ec8 github.com: https://github.com/aureuserp/aureuserp/releases/tag/v1.3.0-BETA1

Credits

๐Ÿ” kkc73 (VulDB User)