First published: Mon Nov 14 2022(Updated: )
A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbar_search.html of the component Search. The manipulation of the argument q leads to cross site scripting. The attack may be launched remotely. The name of the patch is bfab7191543961c6cb77fe267063877c31b616ce. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213560.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Frappe LMS | <=14.14.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3988 is medium.
The affected software of CVE-2022-3988 is Frappe version up to 14.14.3.
The vulnerability type of CVE-2022-3988 is cross-site scripting (XSS).
To fix CVE-2022-3988, update Frappe to a version that includes the fix.
Yes, you can find references for CVE-2022-3988 at the following links: - [GitHub Commit](https://github.com/frappe/frappe/commit/bfab7191543961c6cb77fe267063877c31b616ce) - [GitHub Pull Request](https://github.com/frappe/frappe/pull/18847) - [VulDB Entry](https://vuldb.com/?id.213560)