A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 46.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 46.00 |
VPI formula vpi-v1