PT-2022-25072 · Frappe · Frappe

Jll-02

·

Published

2022-11-14

·

Updated

2022-11-16

·

CVE-2022-3988

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe (affected versions not specified)
Description A problematic issue was found in Frappe, affecting some unknown functionality of the file frappe/templates/includes/navbar/navbar search.html of the component Search. The manipulation of the q argument leads to cross-site scripting. The attack may be launched remotely.
Recommendations Apply a patch to fix this issue, specifically the patch bfab7191543961c6cb77fe267063877c31b616ce. As a temporary workaround, consider restricting the use of the q argument in the affected Search component until the patch is applied.

Fix

Improper Neutralization

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-3988

Affected Products

Frappe