Description
An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer. This issue affects ERPNext: 16.16.0.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
16.16.0
Credits
Fluid Attacks' AI SAST Scanner
Oscar Naveda
References
fluidattacks.com/es/advisories/weeknd
fluidattacks.com/es/advisories/weeknd
github.com/frappe/erpnext