PT-2020-10492 · Frappé Technologies · Erpnext

Published

2020-03-19

·

Updated

2020-03-19

·

CVE-2019-20516

CVSS v3.1

7.4

High

VectorAC:L/AV:N/A:N/C:H/I:N/PR:N/S:C/UI:R
Name of the Vulnerable Software and Affected Versions ERPNext version 11.1.47
Description The issue allows for reflected XSS via the PATH INFO to the "blog/" URI. This means an attacker can inject malicious code into the PATH INFO variable, potentially leading to the execution of unauthorized scripts on the client-side.
Recommendations For ERPNext version 11.1.47, consider restricting access to the "blog/" URI until a patch is available. As a temporary workaround, avoid using the PATH INFO variable in the affected URI to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20516

Affected Products

Erpnext