← العودة للجدول
CVE-2026-104475
CVE-2026-104475 — IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerabilit
📅 2026-10-03
🟡 Medium 🔥 No NVD Vulnerability Web CVSS 5.4

📋 الوصف الكامل

IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims' browsers when served from the /public route.

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-104475

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-104475 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←