CVE-2026-97062
📛 CVE Title
Aureus ERP through 1.6.0 Stored XSS via SVG File Upload
Description
Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- VulnCheck
- CVSS severity
- MEDIUM
- CVSS score
- 5.1 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N- Effective score
- 5.1 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-79 - Reserved
- 2026-09-23
- Published
- 2026-09-24 13:52 UTC
- Last updated
- 2026-09-24 14:58 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/97xxx/CVE-2026-97062.json
NVD / KEV / EPSS data refreshed 2026-09-25 04:28 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85887 - Assigner
- VulnCheck
- Published
- Sep 24, 2026, 1:52:02 PM
- Updated
- Sep 24, 2026, 2:58:04 PM
- EUVD base score (CVSS 4.0)
-
5.1 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N - EUVD-reported EPSS
- 0.0000
- Vendors
- Webkul
- Products
-
Aureus ERP (0 ≤1.6.0)
- Aliases
-
GHSA-mgqc-836v-2pjm
ENISA description: Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.
EUVD references (6)
- https://github.com/aureuserp/aureuserp/pull/1574
- https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Resources/CompanyResource/Schemas/CompanyForm.php#L196-L200
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Clusters/Settings/Pages/ManageBranding.php#L65-L84
- https://github.com/aureuserp/aureuserp
- https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-svg-file-upload
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Webkul | Aureus ERP |
0 (affected)
|
— |
Vendor references (6)
References embedded in the original CVE record by the assigning CNA.
- Pull Request #1574 patchissue-tracking
- https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp third-party-advisory
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Resources/CompanyResource/Schemas/CompanyForm.php#L196-L200 technical-description
- https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Clusters/Settings/Pages/ManageBranding.php#L65-L84 technical-description
- https://github.com/aureuserp/aureuserp product
- VulnCheck Advisory: Aureus ERP through 1.6.0 Stored XSS via SVG File Upload third-party-advisory
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (10)
-
web:aviatrix.ai
Microsoft's September 2026 patch Tuesday addressed a record 972 vulnerabilities, including 112 critical flaws, highlighting AI-powered vulnerability discovery impact.
2026-09-25 10:43 UTC -
web:cybersecuritynews.com
Microsoft released its March 2026 Patch Tuesday security update on March 10, 2026 , addressing 78 vulnerabilities across a wide range of products, including Windows, Microsoft Office, Azure, SQL Server, and .NET.
2026-09-25 10:43 UTC -
web:learn.microsoft.com
This update installs the complete .NET Framework 3.5 product for Windows 11, version 26H1 (build version 28000) and newer. Unlike traditional cumulative updates that patch individual components, this update delivers the full .NET Framework 3.5 product as a standalone installer. It replaces any previously installed version.
2026-09-25 10:43 UTC -
web:patchmypc.com
You can find the production release history below for 2026 .
2026-09-25 10:43 UTC -
web:patchstack.com
Yesterday we wrote up CVE - 2026 -87902, the unauthenticated local file inclusion in WordPress page template resolution fixed in 7.1.2. That post covered the sink,
2026-09-25 10:43 UTC -
web:sec.cloudapps.cisco.com
On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...
2026-09-25 10:43 UTC -
web:windowsmanagementexperts.com
The Microsoft September 2026 Patch Tuesday release fixes up to 974 vulnerabilities, including active zero-days. Here's how IT teams should prioritize patching.
2026-09-25 10:43 UTC -
web:www.aikido.dev
CVE remediation is fixing known flaws in the software you run. Why upgrading often fails, what remediation actually involves, and how backporting fixes it.
2026-09-25 10:43 UTC -
web:www.cisecurity.org
Microsoft reports CVE - 2026 -56164 has been exploited in the wild. CVE - 2026 -56164 may allow remote cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. Microsoft noted that integrating its Antimalware Scan Interface (AMSI) can provide temporary mitigation by actively scanning and detecting malicious POST requests associated with exploitation attempts. The ...
2026-09-25 10:43 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's September 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-09-25 10:43 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-97062.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97062",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T14:57:04.998484Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:58:04.897Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/aureuserp/aureuserp",
"product": "Aureus ERP",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.6.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-22T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:23:31.614Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1574",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/aureuserp/aureuserp/pull/1574"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Resources/CompanyResource/Schemas/CompanyForm.php#L196-L200"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Clusters/Settings/Pages/ManageBranding.php#L65-L84"
},
{
"tags": [
"product"
],
"url": "https://github.com/aureuserp/aureuserp"
},
{
"name": "VulnCheck Advisory: Aureus ERP through 1.6.0 Stored XSS via SVG File Upload",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-svg-file-upload"
}
],
"title": "Aureus ERP through 1.6.0 Stored XSS via SVG File Upload",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-97062",
"datePublished": "2026-09-24T13:52:02.569Z",
"dateReserved": "2026-09-23T23:51:32.671Z",
"dateUpdated": "2026-09-24T14:58:04.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}