CVE-2019-20519
19.03.2020, 18:15
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
Vendor | Product | Version |
---|---|---|
frappe | erpnext | 11.1.47 |
𝑥
= Vulnerable software versions
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
Vendor | Product | Version |
---|---|---|
frappe | erpnext | 11.1.47 |