Junglewise Threat Intelligence

CVE-2026-93454: Aureus ERP Payment Term stored cross-site scripting

CVE-2026-93454 · Severity: medium · CVSS 5.4 · Published 2026-09-18

Executive brief

Aureus ERP, an open-source enterprise resource planning platform, contains a vulnerability in its Accounting plugin where user-supplied text in Payment Term notes is stored without sanitization and rendered as raw HTML. Authenticated users with appropriate permissions can inject arbitrary JavaScript code that executes in the browsers of all other users viewing the affected Payment Term record, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of other users.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the Payment Term note field of the Aureus ERP Accounting plugin. The vulnerable component fails to sanitize user input before storing it in the database and subsequently renders it as raw HTML without proper encoding. An authenticated user with payment-term create permission can submit malicious JavaScript through the payment-terms endpoint, which persists in the database and executes in the browsers of any user viewing that Payment Term record. The attack requires authentication and the appropriate permission, but affects all users who access the affected data. Patches or updates are not explicitly mentioned in the advisory.

Affected products

  • Aureus ERP Aureus ERP through 1.6.0

Timeline

  • 2026-09-18: disclosed

References