CVE-2019-20520 | ERPNext 11.1.47 api/method/ PATH_INFO Reflected cross site scripting
A vulnerability, which was classified as problematic, has been found in ERPNext 11.1.47. Affected by this issue is some unknown functionality of the file api/method/. The manipulation of the argument PATH_INFO leads to cross site scripting (Reflected).
This vulnerability is handled as CVE-2019-20520. The attack may be launched remotely. There is no exploit available.