PT-2022-26042 · Frappe · Frappe
Carlos Bello
·
Published
2022-11-25
·
Updated
2022-11-30
·
CVE-2022-41712
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Frappe version 14.10.0
Description
The issue allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the
import file parameter.Recommendations
For Frappe version 14.10.0, update to a version that correctly validates user-injected information in the
import file parameter to prevent remote file access. As a temporary workaround, consider restricting access to the import file parameter until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frappe