ZeroHour

CVE-2022-23058

PoC
CVSS 2.0
3.5 low
EPSS
<1%p56
Published
()
Modified
Description

ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.

Vendors
frappe
Products
erpnext
Weakness
CWE-79
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N

In the news

No ingested article mentions this CVE yet.