medium · CVSS v3 5.4 · CVSS v4 5.1
CVE-2026-104475
IDURAR ERP CRM version 4.1.1 has a stored XSS vulnerability that allows authenticated users to upload unsanitized SVG files. Malicious scrip
Overview
IDURAR ERP CRM version 4.1.1 has a stored XSS vulnerability that allows authenticated users to upload unsanitized SVG files. Malicious scripts can execute in other users' browsers when served from the /public route, enabling session hijacking or defacement.
Description
IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims' browsers when served from the /public route.
Impact
Confidentiality: attackers can steal session cookies or other sensitive data. Integrity: malicious scripts can modify page content or perform actions on behalf of users. Availability: not directly impacted. Impacted parties: authenticated users of the ERP system, administrators, and any users who view the uploaded SVGs.
Remediation
Apply the vendor's patch that sanitizes SVG uploads or restrict file types to safe formats. If a patch is unavailable, disable SVG upload or enforce strict MIME type validation and content security policy. Additionally, serve uploaded files from a separate domain with CSP headers.
Risk context
The vulnerability has a medium severity score (CVSS 5.4) and no EPSS data, indicating moderate risk. Defenders should prioritize patching or mitigation promptly to prevent potential XSS exploitation.
Affected products
- IDURAR ERP CRM 4.1.1
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 5.4
- CVSS v4
- 5.1
- EPSS
- —