Skip to content

Cross-Site Scripting (XSS) Attack on exceptions and Blog Page

Moderate
ankush published GHSA-439c-3956-r8q7 Dec 11, 2023

Package

frappe (frappe)

Affected versions

<14.49.0

Patched versions

14.49.0

Description

Summary

A specifically crafted payload in request URL can inject HTML on blog page and exception pages.

Impact

XSS attack can be performed if the user clicks on specifically crafted links. As far as we know, the impact is limited and can not be exploited further other than basic XSS. It's still recommended to update your site.

Severity

Moderate

CVE ID

CVE-2023-51769

Weaknesses

No CWEs

Credits