PT-2026-33781 · Unknown · Erp Online

Acme

+1

·

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-6651

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ERP Online versions prior to 4.0.0
Description A cross site scripting flaw exists in the Inventory Edit Item Page component. Remote attackers can exploit this by manipulating the Item Name argument.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6651

Affected Products

Erp Online