Reflected XSS Vulnerability in ERPNext by Frappe Technologies
CVE-2019-20515

7.4HIGH

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
19 March 2020

What is CVE-2019-20515?

ERPNext version 11.1.47 is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability. This flaw exists due to improper handling of user input within the PATH_INFO variable when accessed through specific URIs. An attacker can exploit this vulnerability by crafting a malicious link that redirects users to a compromised address, allowing the attacker to execute arbitrary scripts in the context of the victim's browser. This could lead to unauthorized actions or data exposure.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.