VYPR
Unrated severityNVD Advisory· Published Jun 22, 2022· Updated Jun 17, 2026

CVE-2022-23056

CVE-2022-23056

Description

In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Frappe/Erpnext5 versions
    cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*range: >=13.0.1,<13.30.0
    • cpe:2.3:a:frappe:erpnext:13.0.0:beta13:*:*:*:*:*:*
    • cpe:2.3:a:frappe:erpnext:13.0.0:beta14:*:*:*:*:*:*
    • (no CPE)range: v13.0.0-beta.13 - v13.30.0
    • (no CPE)range: v13.0.0-beta.13

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.