Reflected XSS Vulnerability in ERPNext by Frappe Technologies
CVE-2019-20515
7.4HIGH
What is CVE-2019-20515?
ERPNext version 11.1.47 is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability. This flaw exists due to improper handling of user input within the PATH_INFO variable when accessed through specific URIs. An attacker can exploit this vulnerability by crafting a malicious link that redirects users to a compromised address, allowing the attacker to execute arbitrary scripts in the context of the victim's browser. This could lead to unauthorized actions or data exposure.
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
