PT-2023-29860 · Frappe · Frappe
Cogk
·
Publicado
2023-10-23
·
Atualizado
2023-10-31
·
CVE-2023-46127
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Frappe versions prior to 14.49.0
Description
Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection.
Recommendations
For versions prior to 14.49.0, update to version 14.49.0 to resolve the issue. As a temporary workaround, consider restricting access to document creation for malicious users until the patch is applied.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Frappe