Back

MEDIUM

Aureus ERP 1.6.0 Stored XSS via SVG File Upload

Published Sep 24, 2026

Description

Aureus ERP through 1.6.0, fixed in commit 53ad76d, stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (1)
  1. MITRE
    • CVSS vector changed from CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N to CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 24, 2026
Updated Oct 2, 2026
Reserved Sep 23, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Deferred
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a