Stored XSS Vulnerability in ERPNext Versions v12.0.9-v13.0.3 Allows Account Takeover

Stored XSS Vulnerability in ERPNext Versions v12.0.9-v13.0.3 Allows Account Takeover

CVE-2022-23058 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.

Learn more about our User Device Pen Test.