Impact
The vulnerability allows an authenticated user to upload an SVG file containing malicious JavaScript that is later served from the public directory. When a victim visits the page that displays the uploaded SVG, the script executes within the victim’s browser context, potentially enabling session hijack, data theft, or defacement. The weakness is a classic Stored XSS flaw (CWE‑79).
Affected Systems
IDURAR ERP CRM versions through 4.1.1 are affected. Any deployment using version 4.1.1 or earlier is at risk, as the insecure upload handling remains unchanged.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate overall risk. Exploitation requires valid user credentials to upload the malicious SVG, so the vulnerability is not publicly exploitable without authentication. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is authenticated file upload, an attacker must acquire legitimate credentials or rely on a compromised user account to deliver the payload.
OpenCVE Enrichment