Vulnerability Details CVE-2022-23056
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.4%
CVSS Severity
CVSS v2 Score 3.5
Products affected by CVE-2022-23056
-
cpe:2.3:a:frappe:erpnext:13.0.0
-
cpe:2.3:a:frappe:erpnext:13.0.1
-
cpe:2.3:a:frappe:erpnext:13.0.2
-
cpe:2.3:a:frappe:erpnext:13.1.0
-
cpe:2.3:a:frappe:erpnext:13.1.1
-
cpe:2.3:a:frappe:erpnext:13.10.0
-
cpe:2.3:a:frappe:erpnext:13.10.1
-
cpe:2.3:a:frappe:erpnext:13.10.2
-
cpe:2.3:a:frappe:erpnext:13.11.0
-
cpe:2.3:a:frappe:erpnext:13.11.1
-
cpe:2.3:a:frappe:erpnext:13.12.0
-
cpe:2.3:a:frappe:erpnext:13.12.1
-
cpe:2.3:a:frappe:erpnext:13.13.0
-
cpe:2.3:a:frappe:erpnext:13.14.0
-
cpe:2.3:a:frappe:erpnext:13.14.1
-
cpe:2.3:a:frappe:erpnext:13.15.0
-
cpe:2.3:a:frappe:erpnext:13.15.1
-
cpe:2.3:a:frappe:erpnext:13.15.2
-
cpe:2.3:a:frappe:erpnext:13.16.0
-
cpe:2.3:a:frappe:erpnext:13.16.1
-
cpe:2.3:a:frappe:erpnext:13.17.0
-
cpe:2.3:a:frappe:erpnext:13.18.0
-
cpe:2.3:a:frappe:erpnext:13.19.0
-
cpe:2.3:a:frappe:erpnext:13.2.0
-
cpe:2.3:a:frappe:erpnext:13.2.1
-
cpe:2.3:a:frappe:erpnext:13.20.0
-
cpe:2.3:a:frappe:erpnext:13.20.1
-
cpe:2.3:a:frappe:erpnext:13.21.0
-
cpe:2.3:a:frappe:erpnext:13.21.1
-
cpe:2.3:a:frappe:erpnext:13.22.0
-
cpe:2.3:a:frappe:erpnext:13.22.1
-
cpe:2.3:a:frappe:erpnext:13.23.0
-
cpe:2.3:a:frappe:erpnext:13.23.1
-
cpe:2.3:a:frappe:erpnext:13.23.2
-
cpe:2.3:a:frappe:erpnext:13.23.3
-
cpe:2.3:a:frappe:erpnext:13.24.0
-
cpe:2.3:a:frappe:erpnext:13.25.0
-
cpe:2.3:a:frappe:erpnext:13.25.1
-
cpe:2.3:a:frappe:erpnext:13.25.2
-
cpe:2.3:a:frappe:erpnext:13.26.0
-
cpe:2.3:a:frappe:erpnext:13.27.0
-
cpe:2.3:a:frappe:erpnext:13.27.1
-
cpe:2.3:a:frappe:erpnext:13.28.0
-
cpe:2.3:a:frappe:erpnext:13.29.0
-
cpe:2.3:a:frappe:erpnext:13.29.1
-
cpe:2.3:a:frappe:erpnext:13.29.2
-
cpe:2.3:a:frappe:erpnext:13.3.0
-
cpe:2.3:a:frappe:erpnext:13.3.1
-
cpe:2.3:a:frappe:erpnext:13.4.0
-
cpe:2.3:a:frappe:erpnext:13.4.1
-
cpe:2.3:a:frappe:erpnext:13.5.0
-
cpe:2.3:a:frappe:erpnext:13.5.1
-
cpe:2.3:a:frappe:erpnext:13.5.2
-
cpe:2.3:a:frappe:erpnext:13.6.0
-
cpe:2.3:a:frappe:erpnext:13.7.0
-
cpe:2.3:a:frappe:erpnext:13.7.1
-
cpe:2.3:a:frappe:erpnext:13.8.0
-
cpe:2.3:a:frappe:erpnext:13.9.0
-
cpe:2.3:a:frappe:erpnext:13.9.1
-
cpe:2.3:a:frappe:erpnext:13.9.2