This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Suriq - Always on Watch
suriq.io
did:plc:6vjp7fbgz5ductueireifliv
ERPNext has a SQL injection flaw (CVE-2026-12895): a low-privilege user can read the entire database through a supplier record's name, admin passwords and integration tokens included.
Affects ERPNext below 15.111.0 and 16.22.0.
Fix: upgrade now, then rotate secrets.
https://suriq.io/blog/erpnext-cve-2026-12895-supplier-sql-injection
2026-07-29T11:28:16.271Z