Описание
Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular whitelisted method can result in access to data which the user doesn't have permission to access. Versions 14.64.0 and 15.0.0 contain a patch for this issue. No known workarounds are available.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 14.64.0 (исключая)
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00388
Низкий
7.5 High
CVSS3
Дефекты
CWE-89
EPSS
Процентиль: 59%
0.00388
Низкий
7.5 High
CVSS3
Дефекты
CWE-89