CVE-2022-23058
LOW 3.5EPSS 0.8%
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.
- CVSS v2.0
- 3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N - EPSS
- 0.83% chance of exploitation in the next 30 days, 55th percentile
- Published
- 2022-06-22
- Updated
- 2024-09-16