Vulnerability Description
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frappe | Frappe | >= 12.0.0, <= 12.0.8 |
Related Weaknesses (CWE)
References
- https://github.com/frappe/frappe/pull/8262ExploitPatchThird Party Advisory
- https://github.com/frappe/frappe/pull/8262ExploitPatchThird Party Advisory
FAQ
What is CVE-2019-15700?
CVE-2019-15700 is a vulnerability with a CVSS score of 6.1 (MEDIUM). public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
How severe is CVE-2019-15700?
CVE-2019-15700 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15700?
Check the references section above for vendor advisories and patch information. Affected products include: Frappe Frappe.