cve/2022/CVE-2022-23058.md
2024-06-18 02:51:15 +02:00

835 B
Raw Permalink Blame History

CVE-2022-23058

Description

ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the username field in my settings which can lead to full account takeover.

POC

Reference

Github

No PoCs found on GitHub currently.