CVE-2026-97062: Aureus ERP through 1.6.0 Stored XSS via SVG File Upload

Published Sep 24, 2026
·
Updated

Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.

Affected Software

1 affected component
Aureus ERP<=1.6.0

Event History

Sep 24, 2026
CVE Published
via MITRE·01:52 PM
Data Sourced
via MITRE·01:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Aureus ERP user who can upload an SVG file can exploit it. Exploitation also requires a victim to open the uploaded SVG directly through its application-hosted URL.

2

What is the impact if a victim opens a malicious uploaded SVG?

JavaScript embedded in the SVG can execute in the application's origin. This can enable theft of the victim's session cookie and CSRF token, and may allow actions to be performed in the victim's authenticated context.

3

Are uploads stored in a way that makes this cross-site scripting issue reachable?

Yes. Affected versions store uploaded SVG files on the public disk and serve them from the same origin as the application, so opening the file URL directly can trigger the embedded script.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203