Stored XSS in Aureus ERP Payment Term Note Field
CVE-2026-93454
Key Information:
- Vendor
Webkul
- Status
- Vendor
- CVE Published:
- 17 September 2026
Badges
What is CVE-2026-93454?
The Aureus ERP system version 1.6.0 is susceptible to stored Cross-Site Scripting (XSS) via the Payment Term note field. An authenticated user possessing the permission to create payment terms can submit unvalidated JavaScript code, which is stored in the database and executed in the browsers of all users accessing that Payment Term record. This vulnerability can lead to significant security risks by allowing unauthorized execution of scripts, potentially compromising user data and system integrity.
Affected Version(s)
Aureus ERP 0 <= 1.6.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
