Description
Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record's Chatter panel.
Published: 2026-09-21
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Aureus ERP versions prior to 1.6.0 contain a stored cross‑site scripting flaw in the Chatter field‑change log, where old and new value entries are rendered without escaping. An attacker who can edit tracked text fields can inject malicious markup that executes when any other user, including administrators, opens the record's Chatter panel, potentially compromising confidentiality, integrity or availability of the session or data.

Affected Systems

Aureus ERP, versions before 1.6.0.

Risk and Exploitability

The vulnerability has a CVSS score of 5.1, indicating moderate severity. EPSS data is not available, but the flaw is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with permission to edit tracked text fields; the attacker then delivers the malicious payload that runs in the browser of any viewer of the Chatter panel. Because the payload executes in the victim’s context, it can steal cookies, deface the application or exfiltrate data. The attack vector is inferred to be authenticated, local to the application, and may be carried out by ordinary staff or malicious insiders.

Generated by OpenCVE AI on September 21, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Aureus ERP to version 1.6.0 or later where the Chatter field‑change log is properly escaped.
  • Restrict edit permissions on tracked text fields to trusted users or roles to limit the ability to inject malicious content.
  • Apply input validation and output escaping to all user‑supplied text fields as an ongoing preventive measure.

Generated by OpenCVE AI on September 21, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Aureuserp
Aureuserp aureuserp
Vendors & Products Aureuserp
Aureuserp aureuserp

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record's Chatter panel.
Title Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Aureuserp Aureuserp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-06T13:37:04.825Z

Reserved: 2026-09-21T13:09:30.374Z

Link: CVE-2026-94387

cve-icon Vulnrichment

Updated: 2026-09-21T15:17:15.016Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T14:17:30.340

Modified: 2026-09-28T16:17:18.013

Link: CVE-2026-94387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:23:49Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')