Security Advisory

CVE-2019-15700

6.1
MEDIUM

Vulnerability Description

public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
Published Date August 27, 2019
Official Source NIST NVD Advisory