CVE-2022-3988: Frappe Search navbar_search.html cross site scripting
A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbarsearch.html of the component Search. The manipulation of the argument q leads to cross site scripting. The attack may be launched remotely. The name of the patch is bfab7191543961c6cb77fe267063877c31b616ce. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213560.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch bfab7191543961c6cb77fe267063877c31b616ce - Compensating control
As a mitigation, restrict remote access/requests to the Frappe Search navbar search functionality that processes the q argument until the patch bfab7191543961c6cb77fe267063877c31b616ce is applied (VDB-213560).
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3988?
The severity of CVE-2022-3988 is medium.
What is the affected software of CVE-2022-3988?
The affected software of CVE-2022-3988 is Frappe version up to 14.14.3.
What is the vulnerability type of CVE-2022-3988?
The vulnerability type of CVE-2022-3988 is cross-site scripting (XSS).
How can I fix CVE-2022-3988?
To fix CVE-2022-3988, update Frappe to a version that includes the fix.
Are there any references for CVE-2022-3988?
Yes, you can find references for CVE-2022-3988 at the following links: - [GitHub Commit](https://github.com/frappe/frappe/commit/bfab7191543961c6cb77fe267063877c31b616ce) - [GitHub Pull Request](https://github.com/frappe/frappe/pull/18847) - [VulDB Entry](https://vuldb.com/?id.213560)