Impact
An authenticated user with data import privileges can include arbitrary script code in column header names. Because the framework does not escape these headers when rendering import previews or results, the script executes in the browser of any user who subsequently views the affected interface, resulting in a stored cross‑site scripting vulnerability.
Affected Systems
Frappe framework is affected. Any installation running a version earlier than 16.19.0 or 15.109.0 is vulnerable. The weakness exists in the Data Import functionality across these releases.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability is exploitable by an authenticated importer; any subsequent user who views the import preview or results can be impacted. The attack vector is a stored cross‑site scripting through unsanitized data import headers.
OpenCVE Enrichment