ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the api/method/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the addresses/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the contact/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the api/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the project/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the user/ URI, as demonstrated by a crafted e-mail address.
ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the address/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATHINFO to the blog/ URI.
ERPNext 11.1.47 allows blog?blogcategory= Frame Injection.