Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93454— Aureus ERP through 1.6.0 Stored XSS via Payment Term Note

Quick assessment

Affected
Webkul Aureus ERP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Aureus ERP 1.6.0 及之前版本在会计插件中存储“付款条件备注”字段时未进行过滤,并以原始 HTML 形式渲染。拥有创建付款条件权限的经过身份验证的用户可以向付款条件端点提交任意 JavaScript 代码,该代码会被持久化存储到数据库中,并在所有查看该付款条件记录的用户的浏览器中执行。

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93454

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Aureus ERP through 1.6.0 Stored XSS via Payment Term Note
Source: CVE Program / CVE List V5
Vulnerability Description
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Webkul Aureus ERP 0 ~ 1.6.0 -

II. Public POCs for CVE-2026-93454

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93454

登录查看更多情报信息。

Patches & Fixes for CVE-2026-93454 (1)

Other References for CVE-2026-93454 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93454

No comments yet


Leave a comment