299,584
Total vulnerabilities in the database
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
| Software | From | Fixed in |
|---|---|---|
| frappe / erpnext | 13.0.1 | 13.30.0 |
| frappe / erpnext | 13.0.0-beta14 | 13.0.0-beta14.x |
| frappe / erpnext | 13.0.0-beta13 | 13.0.0-beta13.x |