GHSA-4vx9-xvv3-fqhjMediumCVSS 5.4
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw...
🔗 CVE IDs covered (1)
📋 Description
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-93454
- https://github.com/aureuserp/aureuserp/pull/1562
- https://github.com/aureuserp/aureuserp
- https://github.com/aureuserp/aureuserp/blob/v1.6.0/plugins/webkul/accounts/src/Filament/Resources/PaymentTermResource/Schemas/PaymentTermInfolist.php#L59
- https://hackmd.io/@leediay/stored-xss-aureus-via-payment-term
- https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-payment-term-note
- https://github.com/advisories/GHSA-4vx9-xvv3-fqhj