Back to Database
Status published
High
CVE-2019-20518
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the...
Vulnerability Description
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-20518
Credits & Attribution
No credits recorded in the NVD database.
References
More from frappe
View All →CVE-2025-68953
Certain Frappe requests are vulnerable to Path Traversal
High
7.5
CVE-2025-68929
Frappe may be vulnerable remote code execution due to server-side template injection
Critical
9.1
CVE-2025-68928
Frappe CRM vulnerable to authenticated XSS via website field
Medium
5.4
CVE-2025-67734
Frappe Authenticated Users can Execute JavaScript through its Job Form
Medium
5.1
CVE-2025-67730
Frappe authenticated users can execute XSS through form description fields
Medium
5.1
Affected Vendor
frappe
View all reports →Affected Software
erpnext
Vulnerable Versions:
11.1.47
Timeline
Official Publish:
March 19th, 2020
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:C/UI:R
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.