CVE-2026-94387
Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record's Chatter panel.
| CWE | CWE-79 |
| Vendor | aureuserp |
| Product | aureuserp |
| Published | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for aureuserp aureuserp
Be the first to know when new medium vulnerabilities affecting aureuserp aureuserp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
aureuserp / aureuserp
0 < 1.6.0
References
github.com: https://github.com/aureuserp/aureuserp/commit/57cf5cf4c98d82a0ad89003402f27823fbe1e27c github.com: https://github.com/aureuserp/aureuserp/pull/1465 github.com: https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L165 github.com: https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L182 hackmd.io: https://hackmd.io/@leediay/stored-xss-aureuserp-chatter github.com: https://github.com/aureuserp/aureuserp/releases/tag/v1.6.0 github.com: https://github.com/aureuserp/aureuserp vulncheck.com: https://www.vulncheck.com/advisories/aureus-erp-before-1.6.0-stored-xss-via-chatter-field-change-log
Credits
leediay153