PT-2024-21653 · Frappe · Frappe

H4X0Rl33Tx

+1

·

Published

2024-03-20

·

Updated

2025-07-31

·

CVE-2024-27105

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 14.66.3 Frappe versions prior to 15.16.0
Description Frappe is a full-stack web application framework. The issue allows file permission to be bypassed using certain endpoints, granting less privileged users permission to delete or clone a file.
Recommendations For versions prior to 14.66.3, update to version 14.66.3 or later to resolve the issue. For versions prior to 15.16.0, update to version 15.16.0 or later to resolve the issue.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-27105
GHSA-HQ5V-Q29V-7RCW

Affected Products

Frappe