Reflected Cross-Site Scripting Vulnerability in ERPNext by Frappe Technologies
CVE-2019-20519

7.4HIGH

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
19 March 2020

What is CVE-2019-20519?

ERPNext version 11.1.47 is susceptible to reflected cross-site scripting (XSS) attacks. This vulnerability can be exploited when a user is deceived into clicking on a crafted link that includes a malicious payload in the PATH_INFO of the user/ URI. Successful exploitation allows attackers to inject arbitrary scripts that can execute in the context of the user's browser. This poses a significant risk as it can lead to unauthorized actions being performed on behalf of the victim or sensitive data being compromised.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.