Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Cogk

#47148de 53,632
5.4CVSS total
Vulnerabilidades · 1
PT-2023-29860
5.4
2023-10-23
Frappe · Frappe · CVE-2023-46127
**Name of the Vulnerable Software and Affected Versions** Frappe versions prior to 14.49.0 **Description** Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. **Recommendations** For versions prior to 14.49.0, update to version 14.49.0 to resolve the issue. As a temporary workaround, consider restricting access to document creation for malicious users until the patch is applied.