Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrv3-jc3h-f3m6

Опубликовано: 25 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8

Описание

Frappe vulnerable to information disclosure leading to account takeover

Impact

Making crafted requests could lead to information disclosure that could further lead to account takeover.

Workarounds

There's no workaround to fix this without upgrading.

Credits

Thanks to Thanh of Calif.io for reporting the issue

Пакеты

Наименование

frappe

pip
Затронутые версииВерсия исправления

< 14.89.0

14.89.0

Наименование

frappe

pip
Затронутые версииВерсия исправления

>= 15.0.0, < 15.51.0

15.51.0

EPSS

Процентиль: 33%
0.00133
Низкий

8 High

CVSS4

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. There's no workaround to fix this without upgrading.

EPSS

Процентиль: 33%
0.00133
Низкий

8 High

CVSS4

Дефекты

CWE-200