Sagar Vora

2 exploits Active since Jun 2022
CVE-2022-23057 WRITEUP MEDIUM WRITEUP
ERPNext 12.0.9-13.0.3 - Stored Cross-Site Scripting in Profile Input Fields
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.
CVSS 5.4
CVE-2022-23058 WRITEUP WRITEUP
ERPNext 12.0.9-13.0.3 - Stored Cross-Site Scripting in Username Field
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.