CVE Database
/

CVE-2022-23057

Back to search

CVE-2022-23057

Published: Jun 22, 2022

Modified: Sep 16, 2024

PUBLISHED

Description

In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.

VendorProductVersions

frappe

frappe

affected
v12.0.9 - < unspecified
affected
unspecified - <= v13.0.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now