Stored Cross-Site Scripting in IDURAR ERP CRM Affects Multiple Users
CVE-2026-104475
5.1MEDIUM
What is CVE-2026-104475?
The IDURAR ERP CRM version 4.1.1 is exposed to a stored cross-site scripting vulnerability. This weakness allows authenticated users to upload unsanitized SVG files, which can contain malicious JavaScript. When these files are served from the web application, the scripts execute in the context of other users' browsers, potentially leading to session hijacking, data theft, or unauthorized actions. The vulnerability can be triggered through the profile update or settings upload functions, emphasizing the need for stringent input validation and user input sanitization.
Affected Version(s)
idurar-erp-crm 0 <= 4.1.1
