Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
Medium CVSS 6.1
Summary
Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/frappe/frappe/compare/v14.48.1...v14.49.0
- https://github.com/frappe/frappe/security/advisories/GHSA-439c-3956-r8q7
Timeline
- nvd_ingest NVD