← Back to search

CVE-2026-94387

5.4 MEDIUMpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
A stored cross-site scripting vulnerability in Aureus ERP before 1.6.0 allows users to inject malicious markup via Chatter field-change logs, potentially leading to client-side code execution when viewed by other users.
Exploitability
Exploitation requires user interaction and permission to edit tracked text fields; moderate effort needed for attackers.
Blast radius
If exploited, the vulnerability could impact any user viewing the affected record's Chatter panel, including administrators.
Prioritized remediation
Update to Aureus ERP version 1.6.0 or later to mitigate the vulnerability.
xsswebuser-interaction-required

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record's Chatter panel.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.