CVE-2019-20515: XSS
Published Mar 19, 2020
·Updated
ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the addresses/ URI.
Affected Software
1 affected component
Frappe ERPNext=11.1.47
Event History
Mar 19, 2020
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2019-20515?
The severity of CVE-2019-20515 is high (6.1).
2
How does ERPNext 11.1.47 allow reflected XSS via the PATH_INFO to the addresses/ URI?
ERPNext 11.1.47 allows reflected XSS by not properly sanitizing user input in the PATH_INFO parameter of the addresses/ URI, which can be exploited by an attacker to inject and execute malicious scripts.
3
How can I check if my version of ERPNext is affected by CVE-2019-20515?
You can check if your ERPNext version is affected by CVE-2019-20515 by verifying if it is version 11.1.47.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2019-20515?
The Common Weakness Enumeration (CWE) ID associated with CVE-2019-20515 is CWE-79.
5
Where can I find more information about CVE-2019-20515?
You can find more information about CVE-2019-20515 at the following link: [https://www.netsparker.com/web-applications-advisories/ns-19-017-cross-site-scripting-in-erpnext/]