CVE-2022-23057
22.06.2022, 08:15
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.
Vendor | Product | Version |
---|---|---|
frappe | erpnext | 12.0.9 ≤ 𝑥 < 13.1.0 |
𝑥
= Vulnerable software versions