Cross-site scripting in ERPNext - #VU142386
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to take over an administrator account.
The vulnerability exists due to cross-site scripting in profile fields rendered into portal pages when displaying portal pages containing unescaped user-supplied profile data. A remote user can inject malicious script into a profile field to take over an administrator account.
User interaction is required because an administrator must view the affected portal pages.