CVE-2022-23058
ERPNext - Stored XSS in My Settings
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.
Affected products
frappe · frappeWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →