CVE-2026-104475
Received Received - Intake

Stored XSS in IDURAR ERP CRM via Malicious SVG Upload

Vulnerability report for CVE-2026-104475, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims' browsers when served from the /public route.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
idurar idurar_erp_crm 4.1.1
idurar idurar_erp_crm to 4.1.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in IDURAR ERP CRM through version 4.1.1. Authenticated users can upload malicious SVG files containing JavaScript code via profile update or settings upload endpoints. When these files are served from the /public route, the embedded scripts execute in victims' browsers.

Detection Guidance

Check for unauthorized SVG uploads in the /public route or profile settings. Inspect network traffic for POST requests to /api/admin/profile/update or /api/setting/upload/:settingKey with SVG files containing script tags. Review server logs for files served from /public with suspicious JavaScript execution.

Impact Analysis

An attacker could steal session cookies, perform actions on behalf of users, or redirect users to malicious sites. Users with access to the ERP system could unknowingly execute harmful scripts when viewing profiles or settings containing infected SVG files.

Compliance Impact

This XSS vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality principles. For HIPAA, it may expose protected health information if user sessions are hijacked. Both standards require protection against such injection attacks.

Mitigation Strategies

Disable SVG uploads temporarily or implement strict MIME type validation to block non-image SVG files. Sanitize uploaded SVGs using libraries like DOMPurify or svg-hash. Apply Content-Security-Policy headers to block inline scripts. Update to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104475. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart