An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/frappe/frappe/pull/7981 | third party advisory |
https://github.com/frappe/frappe/releases/tag/v11.1.46 | third party advisory |
https://github.com/frappe/frappe/compare/v11.1.45...v11.1.46 | third party advisory patch |