MEDIUM 5.1 NVD
CVE-2026-97062
Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malici
Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.
References
- https://github.com/aureuserp/aureuserp
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugi
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugi
- https://github.com/aureuserp/aureuserp/pull/1574
- https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-09-24 via NVD.
vulnfeed aggregates 11976 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.