« Volver al listado

CVE-2022-23056

Estado: ModificadaBaja (3.5)—

In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-23056",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerabilitylab@mend.io",
      "affectedData": [
        {
          "vendor": "erpnext",
          "product": "erpnext",
          "versions": [
            {
              "status": "affected",
              "version": "v13.0.0-beta.13",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "v13.30.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-06-22T08:15:07.410",
  "references": [
    {
      "url": "https://github.com/frappe/erpnext/blob/21a3ea462aaf319e466c067c2ec406eb9abe6ed3/erpnext/healthcare/page/patient_history/patient_history.js#L288",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "vulnerabilitylab@mend.io"
    },
    {
      "url": "https://www.mend.io/vulnerability-database/CVE-2022-23056",
      "tags": [
        "Exploit",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "vulnerabilitylab@mend.io"
    },
    {
      "url": "https://github.com/frappe/erpnext/blob/21a3ea462aaf319e466c067c2ec406eb9abe6ed3/erpnext/healthcare/page/patient_history/patient_history.js#L288",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.mend.io/vulnerability-database/CVE-2022-23056",
      "tags": [
        "Exploit",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vulnerabilitylab@mend.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack."
    },
    {
      "lang": "es",
      "value": "En ERPNext, versiones v13.0.0-beta.13 hasta v13.30.0, son vulnerables a un ataque de tipo XSS almacenado en la página del historial del paciente, lo que permite a un usuario con pocos privilegios conducir un ataque de toma de control de la cuenta"
    }
  ],
  "lastModified": "2026-06-17T04:29:25.913",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "658B50C9-2AC2-449E-A43B-62EF6092E302",
              "versionEndExcluding": "13.30.0",
              "versionStartIncluding": "13.0.1"
            },
            {
              "criteria": "cpe:2.3:a:frappe:erpnext:13.0.0:beta13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42DE3B99-91F9-49CD-805D-ACA330131025"
            },
            {
              "criteria": "cpe:2.3:a:frappe:erpnext:13.0.0:beta14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94C1D457-5B67-47C9-A28A-8D9662B1CE26"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vulnerabilitylab@mend.io"
}