PT-2023-27906 · Frappe · Frappe

Sagarvora

·

Published

2023-09-06

·

Updated

2023-09-11

·

CVE-2023-41328

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 13.46.1 Frappe versions prior to 14.20.0
Description A SQL Injection issue has been identified in the Frappe Framework, which could allow a malicious actor to access sensitive information.
Recommendations For versions prior to 13.46.1, upgrade to version 13.46.1 or later. For versions prior to 14.20.0, upgrade to version 14.20.0 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-41328
GHSA-53WH-F67G-9679

Affected Products

Frappe