Impact
Aureus ERP versions up to 1.6.0 contain a stored cross‑site scripting flaw in the Accounting plugin; the Payment Term note field is stored without sanitization and rendered as raw HTML when the record is viewed. The flaw is a classic DOM‑based input validation weakness (CWE‑79). An attacker who can submit a note can inject JavaScript that executes in the browsers of every user who views that Payment Term, potentially leading to credential theft, session hijacking, or malicious actions performed on behalf of the victim. The impact spreads across all users with access to the affected records, so confidentiality, integrity, and authentication may be compromised. This is the extent of the documented influence in the CVE description.
Affected Systems
Webkul Aureus ERP version 1.6.0 is affected. Earlier releases prior to 1.6.0 do not contain the flaw. The vulnerability resides in the PaymentTermResource schema of the Accounting plugin.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale reported attacks. Attack requires authenticated users with payment‑term create permission, implying the attacker must first gain legitimate or compromised access. Given the moderate disclosed risk, the likely impact is user‑level XSS that can be mitigated with proper controls.
OpenCVE Enrichment