CVE-2022-23056: ERPNext - Stored XSS leads to account takover
Published Jun 22, 2022
·Updated
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
Affected Software
3 affected components
Frappe ERPNext>=13.0.1<13.30.0
Frappe ERPNext=13.0.0-beta13
Frappe ERPNext=13.0.0-beta14
Remediation
Patch Available
Event History
Jun 22, 2022
CVE Published
via MITRE·07:25 AM
Data Sourced
via MITRE·07:25 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-23056?
The severity of CVE-2022-23056 is medium with a severity value of 5.4.
2
How does the vulnerability CVE-2022-23056 affect ERPNext?
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page.
3
What is the risk of storing XSS in ERPNext Patient History?
The risk of Stored XSS in ERPNext Patient History is that it allows a low privilege user to conduct an account takeover attack.
4
What is the affected software for CVE-2022-23056?
The affected software for CVE-2022-23056 is Frappe ERPNext versions v13.0.0-beta.13 through v13.30.0.
5
How can I fix the vulnerability CVE-2022-23056?
To fix the vulnerability CVE-2022-23056, it is recommended to upgrade to a version higher than v13.30.0.