Impact
Aureus ERP versions prior to 1.6.0 contain a stored cross‑site scripting flaw in the Chatter field‑change log, where old and new value entries are rendered without escaping. An attacker who can edit tracked text fields can inject malicious markup that executes when any other user, including administrators, opens the record's Chatter panel, potentially compromising confidentiality, integrity or availability of the session or data.
Affected Systems
Aureus ERP, versions before 1.6.0.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1, indicating moderate severity. EPSS data is not available, but the flaw is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with permission to edit tracked text fields; the attacker then delivers the malicious payload that runs in the browser of any viewer of the Chatter panel. Because the payload executes in the victim’s context, it can steal cookies, deface the application or exfiltrate data. The attack vector is inferred to be authenticated, local to the application, and may be carried out by ordinary staff or malicious insiders.
OpenCVE Enrichment