Frappe

Erpnext

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.79%
  • Veröffentlicht 19.03.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:38:39

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.

Exploit
  • EPSS 0.79%
  • Veröffentlicht 19.03.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:38:38

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.

Exploit
  • EPSS 0.79%
  • Veröffentlicht 19.03.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:38:38

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.

Exploit
  • EPSS 0.79%
  • Veröffentlicht 19.03.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:38:39

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.

Exploit
  • EPSS 0.79%
  • Veröffentlicht 19.03.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:38:39

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.

Exploit
  • EPSS 0.79%
  • Veröffentlicht 19.03.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:38:39

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.

Exploit
  • EPSS 0.79%
  • Veröffentlicht 19.03.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:38:39

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.

Exploit
  • EPSS 0.79%
  • Veröffentlicht 19.03.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 04:38:39

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.

Exploit
  • EPSS 0.68%
  • Veröffentlicht 18.03.2020 19:15:17
  • Zuletzt bearbeitet 21.11.2024 04:38:38

ERPNext 11.1.47 allows blog?blog_category= Frame Injection.

  • EPSS 1.43%
  • Veröffentlicht 11.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:49

A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the a...