First published: Mon Aug 12 2019(Updated: )
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Frappe LMS | >=11.0.0<11.1.46 | |
Frappe LMS | =10.0.0 | |
Frappe LMS | =12.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Frappe Framework XSS vulnerability is CVE-2019-14967.
The severity of CVE-2019-14967 is medium with a CVSS score of 6.1.
Frappe Framework versions 10 (specifically 10.0.0), 11 (before 11.1.46), and 12 are affected by CVE-2019-14967.
The Common Weakness Enumeration (CWE) ID for CVE-2019-14967 is CWE-79.
To fix the XSS vulnerability in Frappe Framework, update to version 11.1.46 or higher.