CVE-2022-23058

ERPNext 12.0.9-13.0.3 - Stored Cross-Site Scripting in Username Field

Title source: llm
STIX 2.1

Description

ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.

References (2)

Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://www.mend.io/vulnerability-database/CVE-2022-23058

Scores

EPSS 0.0079
EPSS Percentile 51.5%

Details

CWE
CWE-79
Status published
Products (1)
frappe/erpnext 12.0.9 - 13.1.0
Published Jun 22, 2022
Tracked Since Feb 18, 2026