Cc0wkinginc0wking.hashnode.dev00Stored-XSS in ERPNext (Frappe) Email Template EngineApr 3 · 1 min read · I. Description The Email Template engine is vulnerable to Cross-Site Scripting (XSS).An attacker with permission to create or edit email templates can inject malicious javascript code that are executeJoin discussion
Cc0wkinginc0wking.hashnode.dev00SSTI in ERPNext (Frappe) Email Template EngineApr 3 · 1 min read · I. Description The Email Template engine is vulnerable to Server-Side Template Injection (SSTI).An attacker with permission to create or edit email templates can inject template expressions that are eJoin discussion