Stored Cross-Site Scripting in IDURAR ERP CRM Affects Multiple Users
CVE-2026-104475

5.1MEDIUM

Key Information:

Vendor

Idurar

Vendor
CVE Published:
2 October 2026

What is CVE-2026-104475?

The IDURAR ERP CRM version 4.1.1 is exposed to a stored cross-site scripting vulnerability. This weakness allows authenticated users to upload unsanitized SVG files, which can contain malicious JavaScript. When these files are served from the web application, the scripts execute in the context of other users' browsers, potentially leading to session hijacking, data theft, or unauthorized actions. The vulnerability can be triggered through the profile update or settings upload functions, emphasizing the need for stringent input validation and user input sanitization.

Affected Version(s)

idurar-erp-crm 0 <= 4.1.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jashn Wahi
.