CVE Database
/

CVE-2022-23058

Back to search

CVE-2022-23058

Published: Jun 22, 2022

Modified: Sep 16, 2024

PUBLISHED

Description

ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.

VendorProductVersions

frappe

frappe

affected
v12.0.9 - < unspecified
affected
unspecified - <= v13.0.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now