MEDIUM

CVE-2026-93454

2026-09-18 CVSS v3.1
CVSS
5.4

Description

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.17%
Probability of exploitation in next 30 days
6.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE