Description
An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interpolates tag content into HTML attributes and element content without escaping. This issue affects Frappe: 16.10.10.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
16.10.10
Credits
Fluid Attacks' AI SAST Scanner
Oscar Uribe
References
fluidattacks.com/es/advisories/silvio
fluidattacks.com/es/advisories/silvio
github.com/frappe/frappe