PT-2022-26042 · Frappe · Frappe

Carlos Bello

·

Published

2022-11-25

·

Updated

2022-11-30

·

CVE-2022-41712

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frappe version 14.10.0
Description The issue allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the import file parameter.
Recommendations For Frappe version 14.10.0, update to a version that correctly validates user-injected information in the import file parameter to prevent remote file access. As a temporary workaround, consider restricting access to the import file parameter until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-41712

Affected Products

Frappe