PT-2019-13901 · Frappe · Frappe Framework

Netchampfaris

·

Published

2019-08-12

·

Updated

2019-08-15

·

CVE-2019-14967

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe Framework versions 10, 11 through 11.1.45, and 12
Description An issue was discovered that results in an XSS vulnerability.
Recommendations For Frappe Framework version 10, update to a version after 10. For Frappe Framework version 11, update to version 11.1.46 or later. For Frappe Framework version 12, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14967

Affected Products

Frappe Framework