VendorsFrappeerpnext11.1.47
Vulnerabilities

Frappe ERPNext 11.1.47

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2019-20514
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
Published 2020-03-19 · Modified
7.4EPSS 0.008
CVE-2019-20515
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
Published 2020-03-19 · Modified
7.4EPSS 0.008
CVE-2019-20516
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
Published 2020-03-19 · Modified
7.4EPSS 0.008
CVE-2019-20517
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
Published 2020-03-19 · Modified
7.4EPSS 0.008
CVE-2019-20518
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
Published 2020-03-19 · Modified
7.4EPSS 0.008
CVE-2019-20519
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
Published 2020-03-19 · Modified
7.4EPSS 0.008
CVE-2019-20520
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
Published 2020-03-19 · Modified
7.4EPSS 0.008
CVE-2019-20521
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
Published 2020-03-19 · Modified
7.4EPSS 0.008
CVE-2019-20511
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
Published 2020-03-18 · Modified
6.1EPSS 0.007