Vulnerability Description
IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims' browsers when served from the /public route.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/idurar/idurar-erp-crm
- https://github.com/idurar/idurar-erp-crm/blob/4.1.1/backend/src/middlewares/uplo
- https://github.com/idurar/idurar-erp-crm/issues/1414
- https://www.vulncheck.com/advisories/idurar-erp-crm-through-4.1.1-stored-xss-via
FAQ
What is CVE-2026-104475?
CVE-2026-104475 is a vulnerability with a CVSS score of 5.4 (MEDIUM). IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-...
How severe is CVE-2026-104475?
CVE-2026-104475 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-104475?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.