ERPNext
cpe:2.3:a:erpnext:erpnext:*:*:*:*:*:*:*
- <= 15.88.1
A stored cross-site scripting vulnerability has been identified in ERPNext versions through 15.88.1. This issue arises within the CSV import feature when the 'Update Existing Records' option is selected. An attacker can inject malicious JavaScript into a CSV field, which is then saved in the database. The injected script executes when the affected record is viewed in the ERPNext web interface, potentially compromising user sessions or allowing unauthorized actions on behalf of the user.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected record.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.