CVE-2019-20519: XSS
Published Mar 19, 2020
·Updated
ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the user/ URI, as demonstrated by a crafted e-mail address.
Affected Software
1 affected component
Frappe ERPNext=11.1.47
Event History
Mar 19, 2020
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this ERPNext version?
The vulnerability ID for ERPNext version 11.1.47 is CVE-2019-20519.
2
How does this vulnerability occur?
This vulnerability occurs due to a reflected XSS via the PATH_INFO to the user/ URI.
3
What is the severity of CVE-2019-20519?
The severity of CVE-2019-20519 is high with a CVSS score of 6.1.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by crafting a malicious e-mail address.
5
Is there a fix available for this vulnerability?
Yes, it is recommended to upgrade to a fixed version of ERPNext.