Description
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
Published: 2026-09-17
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Aureus ERP versions up to 1.6.0 contain a stored cross‑site scripting flaw in the Accounting plugin; the Payment Term note field is stored without sanitization and rendered as raw HTML when the record is viewed. The flaw is a classic DOM‑based input validation weakness (CWE‑79). An attacker who can submit a note can inject JavaScript that executes in the browsers of every user who views that Payment Term, potentially leading to credential theft, session hijacking, or malicious actions performed on behalf of the victim. The impact spreads across all users with access to the affected records, so confidentiality, integrity, and authentication may be compromised. This is the extent of the documented influence in the CVE description.

Affected Systems

Webkul Aureus ERP version 1.6.0 is affected. Earlier releases prior to 1.6.0 do not contain the flaw. The vulnerability resides in the PaymentTermResource schema of the Accounting plugin.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale reported attacks. Attack requires authenticated users with payment‑term create permission, implying the attacker must first gain legitimate or compromised access. Given the moderate disclosed risk, the likely impact is user‑level XSS that can be mitigated with proper controls.

Generated by OpenCVE AI on September 19, 2026 at 08:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Aureus ERP to the latest available version that includes input sanitization for the Payment Term field
  • If an upgrade is not immediately possible, limit payment‑term create permissions to trusted administrators or temporarily disable the payment‑term entry feature
  • Implement a strict Content Security Policy that blocks inline scripts and restricts JavaScript execution for the affected page

Generated by OpenCVE AI on September 19, 2026 at 08:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Webkul
Webkul aureus Erp
Vendors & Products Webkul
Webkul aureus Erp

Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
Title Aureus ERP through 1.6.0 Stored XSS via Payment Term Note
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Webkul Aureus Erp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-06T13:37:03.140Z

Reserved: 2026-09-17T22:45:31.668Z

Link: CVE-2026-93454

cve-icon Vulnrichment

Updated: 2026-09-22T01:59:45.469Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T00:17:49.853

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-93454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T09:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')