Описание
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:frappe:frappe:11.0.0:-:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:12.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00365
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-306
Связанные уязвимости
github
больше 3 лет назад
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.
EPSS
Процентиль: 58%
0.00365
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-306