CVE-2022-23057

CVE-2022-23057: ERPNext - Stored XSS in My Profile

Vendor Frappe
Product frappe
Weakness CWE-79 · XSS
Published June 22, 2022
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.

Key dates

02Disclosure timeline

June 22, 2022 CVE published
September 16, 2024 Record updated

Related vulnerabilities

04Related CVE