Junglewise Threat Intelligence

CVE-2026-8218: Devs Palace ERP Online XSS in purchase_return_save

CVE-2026-8218 · Severity: low · CVSS 2.4 · Published 2026-05-10

Technologies: Devs Palace ERP Online. Vendors: Devs Palace.

Executive brief

Devs Palace ERP Online, a business management software, contains a security vulnerability in its inventory management module. An attacker could potentially inject malicious scripts into the system, which would then execute in the browsers of other users. This could lead to unauthorized actions being performed on behalf of legitimate users or the theft of session information.

Technical details

A cross-site scripting (XSS) vulnerability exists in Devs Palace ERP Online up to version 4.0.0. The flaw is located within the /inventory/purchase_return_save file, where improper input neutralization allows for the injection of malicious web scripts. An attacker with high privileges can exploit this remotely by submitting crafted data that is later rendered in a victim's browser. Successful exploitation requires user interaction (UI:R) and can lead to unauthorized manipulation of web content. A public proof-of-concept (PoC) exists, but the vendor has not responded to disclosure attempts.

Affected products

  • Devs Palace ERP Online up to 4.0.0

Timeline

  • 2026-05-10: disclosed: Initial public disclosure via VulDB and NVD
  • 2026-05-10: advisory
  • 2026-05-11: other: CISA-ADP SSVC assessment performed

References

Related threats