Unrated severityNVD Advisory· Published Jun 22, 2022· Updated Jun 17, 2026
CVE-2022-23056
CVE-2022-23056
Description
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*range: >=13.0.1,<13.30.0
- cpe:2.3:a:frappe:erpnext:13.0.0:beta13:*:*:*:*:*:*
- cpe:2.3:a:frappe:erpnext:13.0.0:beta14:*:*:*:*:*:*
- (no CPE)range: v13.0.0-beta.13 - v13.30.0
- (no CPE)range: v13.0.0-beta.13
Patches
Vulnerability mechanics
References
2- github.com/frappe/erpnext/blob/21a3ea462aaf319e466c067c2ec406eb9abe6ed3/erpnext/healthcare/page/patient_history/patient_history.jsnvdPatchThird Party Advisory
- www.mend.io/vulnerability-database/CVE-2022-23056nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.