ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
CWE-79
CVE-2019-20519
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
CVE-2019-20520
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
CVE-2019-20521
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
CVE-2019-20522
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter.
CVE-2019-20523
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter.
