PT-2023-27906 · Frappe · Frappe

Sagarvora

·

Publicado

2023-09-06

·

Atualizado

2023-09-11

·

CVE-2023-41328

CVSS v3.1

4.2

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 13.46.1 Frappe versions prior to 14.20.0
Description A SQL Injection issue has been identified in the Frappe Framework, which could allow a malicious actor to access sensitive information.
Recommendations For versions prior to 13.46.1, upgrade to version 13.46.1 or later. For versions prior to 14.20.0, upgrade to version 14.20.0 or later.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-41328
GHSA-53WH-F67G-9679

Produtos afetados

Frappe