MEDIUM
Aureus ERP 1.6.0 Stored XSS via SVG File Upload
Published Sep 24, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.21%
Description
Aureus ERP through 1.6.0, fixed in commit 53ad76d, stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.
Affected products
-
- Version 0StatusaffectedConstraints<=1.6.0
- Version
-
- Version StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Webkul | Aureus ERP | unaffected |
| ||||||
| Webkul | Aureus ERP | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-64818
- https://github.com/aureuserp/aureuserp product
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Clusters/Settings/Pages/ManageBranding.php#L65-L84 technical-description
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Resources/CompanyResource/Schemas/CompanyForm.php#L196-L200 technical-description
- https://github.com/aureuserp/aureuserp/pull/1574 patchissue-tracking
- https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp exploitthird-party-advisory
- https://www.vulncheck.com/advisories/aureus-erp-stored-xss-via-svg-file-upload third-party-advisory
- https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-svg-file-upload third-party-advisory
Change history (1)
- MITRE
- CVSS vector changed from CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N to
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N → CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
- CVSS vector changed from CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N to
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 24, 2026
Updated Oct 2, 2026
Reserved Sep 23, 2026
Link CVE-2026-97062
CISA Vulnrichment
Updated Sep 24, 2026