PT-2026-24784 · Frappe+1 · Frappe
Losevanni
+1
·
Publicado
2026-03-11
·
Atualizado
2026-03-13
·
CVE-2026-31877
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frappe versions prior to 15.84.0 and 14.99.0
Description
Frappe is a full-stack web application framework. A specially crafted request to a certain endpoint could result in SQL injection, potentially allowing an attacker to extract information they wouldn't otherwise be able to access. The issue involves a bypass of access controls due to improper field sanitization.
Recommendations
Update to Frappe version 15.84.0 or 14.99.0.
Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Frappe