{"id":"CVE-2022-28598","details":"Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.","modified":"2026-08-12T03:51:18.373647348Z","published":"2022-08-22T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28598.json"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/171730/ERPNext-12.29-Cross-Site-Scripting.html"},{"type":"WEB","url":"https://github.com/patrickdeanramos/CVE-2022-28598/blob/main/ERPNext%20-%2012.29.0.pdf"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28598.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28598"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frappe/erpnext","events":[{"introduced":"1413af8f3a07d8c9ade54e878e86f450051c3b00"},{"last_affected":"1413af8f3a07d8c9ade54e878e86f450051c3b00"}],"database_specific":{"cpe":"cpe:2.3:a:frappe:erpnext:12.29.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"12.29.0"},{"last_affected":"12.29.0"}],"source":"CPE_STRING"}}],"versions":["12.29.0","v12.29.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28598.json"}}],"schema_version":"1.9.0"}