Cross-site scripting in ERPNext - #VU142402
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in portal pages when rendering stored content from public portal form submissions. A remote attacker can submit crafted markup that is later viewed by staff to execute arbitrary script in a victim's browser.
User interaction is required because staff must review the submitted record.