Executive brief
Aureus ERP is an open-source enterprise resource planning system used to manage business operations and customer relationships. A flaw in the ChatterPanel messaging component fails to restrict message access by the current user's record context, allowing authenticated users to read, edit, delete, or pin messages belonging to other departments or companies by manipulating message IDs. This could expose sensitive business communications and notes across the entire system.
Technical details
The ChatterPanel component in Aureus ERP before version 1.5.0 performs insufficient authorization checks on message lookup operations, failing to scope results to the current record context. An authenticated attacker can enumerate or directly access message IDs from other organizational units and perform write operations (edit, delete, pin) or read all enumerable notes in the system. No special privileges or user interaction is required beyond initial authentication.
Affected products
- Aureus Aureus ERP before 1.5.0
Timeline
- 2026-09-22: disclosed