Junglewise Threat Intelligence

CVE-2026-8262: Devs Palace ERP Online XSS in /accounts/chart-save

CVE-2026-8262 · Severity: low · CVSS 2.4 · Published 2026-05-11

Technologies: Devs Palace ERP Online. Vendors: Devs Palace.

Executive brief

A security vulnerability exists in Devs Palace ERP Online, a business management software suite. An attacker with high-level administrative privileges could inject malicious scripts into the system's accounting module. If another user views the affected area, the script could execute in their browser, potentially leading to unauthorized actions or data manipulation within the application.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Devs Palace ERP Online up to version 4.0.0. The flaw is located within the /accounts/chart-save file, where improper input neutralization allows for the injection of malicious web scripts. An attacker requires high privileges (PR:H) and network access to exploit this vulnerability. Successful exploitation requires a victim to interact with the manipulated page (UI:R), at which point the script executes in the context of the victim's session. A public proof-of-concept exists, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Devs Palace ERP Online up to 4.0.0

Timeline

  • 2026-05-11: disclosed: Initial public disclosure via VulDB and NVD
  • 2026-05-11: advisory

References

Related threats