CVE-2026-97062
5.4 MEDIUMpublic exploit availablePublished 2026-09-24 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Public exploit & PoC references
- https://github.com/aureuserp/aureuserp
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Clusters/Settings/Pages/ManageBranding.php#L65-L84
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Resources/CompanyResource/Schemas/CompanyForm.php#L196-L200
- https://github.com/aureuserp/aureuserp/pull/1574
All references
- https://github.com/aureuserp/aureuserp
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Clusters/Settings/Pages/ManageBranding.php#L65-L84
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Resources/CompanyResource/Schemas/CompanyForm.php#L196-L200
- https://github.com/aureuserp/aureuserp/pull/1574
- https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp
- https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-svg-file-upload
- https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-13533PoC
- MEDIUMCVE-2025-14814
- LOWCVE-2025-15677
- MEDIUMCVE-2025-15696
- LOWCVE-2025-15698
- MEDIUMCVE-2025-36147
- HIGHCVE-2025-61682PoC
- MEDIUMCVE-2025-71419PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.