PT-2022-25072 · Frappe · Frappe

·

CVE-2022-3988

·

Published

2022-11-14

·

Updated

2022-11-16

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe (affected versions not specified)
Description A problematic issue was found in Frappe, affecting some unknown functionality of the file frappe/templates/includes/navbar/navbar search.html of the component Search. The manipulation of the q argument leads to cross-site scripting. The attack may be launched remotely.
Recommendations Apply a patch to fix this issue, specifically the patch bfab7191543961c6cb77fe267063877c31b616ce. As a temporary workaround, consider restricting the use of the q argument in the affected Search component until the patch is applied.

Exploit

Fix

Improper Neutralization

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3988

Affected Products

Frappe