CVE-2019-20511 (erpnext)

ERPNext 11.1.47 allows blog?blog_category= Frame Injection.