Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

A7Mad96

#44107of 53,632
6.1Total CVSS
Vulnerabilities · 1
PT-2024-25685
6.1
2024-05-09
Frappe · Frappe · CVE-2024-34074
**Name of the Vulnerable Software and Affected Versions** Frappe versions prior to 14.74.0 Frappe versions prior to 15.26.0 **Description** The login page of Frappe accepts a redirect argument, allowing redirects to untrusted external URLs. This behavior can be exploited by malicious actors for phishing purposes. **Recommendations** For versions prior to 14.74.0, update to version 14.74.0 to resolve the issue. For versions prior to 15.26.0, update to version 15.26.0 to resolve the issue.