CVE-2019-15700: XSS
Published Aug 27, 2019
·Updated
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
Affected Software
1 affected component
Frappe frappe>=12.0.0<=12.0.8
Remediation
Patch Available
Event History
Aug 27, 2019
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Frappe Framework issue?
The vulnerability ID for this Frappe Framework issue is CVE-2019-15700.
2
What is the title of this vulnerability?
The title of this vulnerability is "public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML...".
3
How does this vulnerability affect Frappe Framework?
This vulnerability affects Frappe Framework versions 12 through 12.0.8.
4
What is the severity of CVE-2019-15700?
The severity of CVE-2019-15700 is medium with a score of 6.1.
5
How can I fix this vulnerability?
To fix this vulnerability, update Frappe Framework to a version higher than 12.0.8.