VYPR
Medium severity6.1NVD Advisory· Published Aug 27, 2019· Updated Jun 17, 2026

CVE-2019-15700

CVE-2019-15700

Description

public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Frappe/Frappe2 versions
    cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*range: >=12.0.0,<=12.0.8
    • (no CPE)range: <=12.0.8
  • Frappe/Frappe Frameworkdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.