Cross-site scripting in ERPNext - #VU142379
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to take over a user's account.
The vulnerability exists due to cross-site scripting in record fields rendered into an attribute context when rendering page content without escaping. A remote user can inject script into stored record fields to take over a user's account.
User interaction is required, and exploitation occurs when a privileged user opens the affected page.