Executive brief
Aureus ERP is a free open-source platform that manages business processes and data. A stored cross-site scripting vulnerability in the Chatter module allows users with field editing permissions to inject malicious code into change logs that executes when other users view those records, potentially enabling account takeover or unauthorized access to sensitive business data.
Technical details
The vulnerability is a stored XSS in the Chatter field-change log component where old_value and new_value entries are rendered without proper HTML escaping. An authenticated user with permission to edit tracked text fields can inject malicious markup that persists in the database and executes in the browsers of any user, including administrators, when they view the affected record's Chatter panel.
Affected products
- Aureus ERP before 1.6.0
Timeline
- 2026-09-21: disclosed