CVE-2026-4175Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php of the component Chatter Message Handler. Executing a manipulation of the argument subject/body can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 1.3.0-BETA1 is sufficient to fix this issue. This patch is called 2135ee7efff4090e70050b63015ab5e268760ec8. It is suggested to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-15: 3Technical Details · 2026-03-15: 203-15
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-4175 A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file plugins/webkul/chatter/resources/views/filament/… https://www.cve.org/CVERecord?id=CVE-2026-4175

    Post summary

    The snippet notes an identified CVE in Aureus ERP with minimal details, primarily pointing to the CVE record without further technical or remedial information.

    00000101
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4175 - Aureus ERP Chatter Message content-text-entry.blade.php cross site scripting Intel Report: https://ift.tt/tjPWw8p

    Post summary

    The tweet announces CVE‑2026‑4175, identifies an XSS flaw in Aureus ERP’s content‑text‑entry.blade.php, and links to an Intel Report for further details.

    0000031
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4175 - Aureus ERP Chatter Message content-text-entry.blade.php cross site scripting Intel Report: https://ift.tt/JQN41nB

    Post summary

    A threat alert announces CVE‑2026‑4175, a cross‑site scripting flaw in Aureus ERP’s Chatter Message content‑text‑entry.blade.php; no PoC, exploit code, patch, or active exploitation is reported.

    0000028
    336 followersView on X

Explore more