{"id":"CVE-2026-94387","published":"2026-09-21T14:17:30.340","lastModified":"2026-09-21T16:17:30.527","description":"Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record's Chatter panel.","cvssScore":5.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/aureuserp/aureuserp","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L165","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L182","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/commit/57cf5cf4c98d82a0ad89003402f27823fbe1e27c","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/pull/1465","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/releases/tag/v1.6.0","tags":[]},{"url":"https://hackmd.io/@leediay/stored-xss-aureuserp-chatter","tags":[]},{"url":"https://www.vulncheck.com/advisories/aureus-erp-before-1.6.0-stored-xss-via-chatter-field-change-log","tags":[]}],"exploitRefs":[{"url":"https://github.com/aureuserp/aureuserp","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L165","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L182","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/commit/57cf5cf4c98d82a0ad89003402f27823fbe1e27c","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/pull/1465","tags":[]},{"url":"https://github.com/aureuserp/aureuserp/releases/tag/v1.6.0","tags":[]}],"hasPoc":true,"ai":{"summary":"A stored cross-site scripting vulnerability in Aureus ERP before 1.6.0 allows users to inject malicious markup via Chatter field-change logs, potentially leading to client-side code execution when viewed by other users.","exploitability":"Exploitation requires user interaction and permission to edit tracked text fields; moderate effort needed for attackers.","blast_radius":"If exploited, the vulnerability could impact any user viewing the affected record's Chatter panel, including administrators.","remediation":"Update to Aureus ERP version 1.6.0 or later to mitigate the vulnerability.","tags":["xss","web","user-interaction-required"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:25:25.289Z"}}