Skip to content

Frappe Authenticated Reflected Cross site scripting (XSS) in portal pages

Moderate
ankush published GHSA-7p3m-h76m-hg9v Feb 6, 2024

Package

frappe (frappe)

Affected versions

< 15.5.0
<14.59.0

Patched versions

15.5.0
14.59.0

Description

Summary

Portal pages are susceptible to XSS which can be used to inject malicious JS code if user clicks on a malicious link.

Workaround

There's no workaround. It's advisable to update your system.

Severity

Moderate

CVE ID

CVE-2024-24812

Weaknesses

Credits