Description
An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escaping This issue affects Frappe: 16.10.0.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
16.10.0
Credits
Fluid Attacks' AI SAST Scanner
Oscar Uribe
References
fluidattacks.com/es/advisories/sabina
github.com/frappe/frappe
github.com/frappe/frappe/pull/38796