Cross-site scripting in ERPNext - #VU127503
Published: April 24, 2026
ERPNext
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in authenticated sessions.
The vulnerability exists due to improper neutralization of input during web page generation in a certain page when handling a malicious URL. A remote attacker can send a specially crafted URL to execute arbitrary JavaScript in authenticated sessions.
User interaction is required because a logged-in user must access the malicious URL.