Executive brief
Workcube ERP, a business management platform used for enterprise resource planning, is vulnerable to a security flaw that allows attackers to inject malicious scripts into web pages. If an employee clicks a specially crafted link, an attacker could potentially steal session information or perform unauthorized actions on behalf of the user. This could lead to unauthorized access to sensitive business data or internal systems.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Holistic IT Workcube ERP due to improper neutralization of user-supplied input during web page generation. The flaw allows a remote, unauthenticated attacker to execute arbitrary JavaScript in the context of a victim's browser session by tricking them into visiting a malicious URL. This vulnerability affects versions V12 through V14 prior to the 'Cognitive' update. Successful exploitation can lead to the disclosure of sensitive information, such as session cookies, or the performance of unauthorized actions within the ERP application.
Affected products
- Holistic IT, Consultancy Coop. Workcube ERP V12 - V14 before Cognitive
Timeline
- 2025-09-16: disclosed
- 2025-09-16: advisory