Description
Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
>= 15.0.0, < 15.74.2
References
github.com/...frappe/security/advisories/GHSA-5p8f-568f-vfq2
github.com/...ommit/93ee30c638bf7a7e33e2937a0adccac14c38b410
github.com/...ommit/c2b01e3eb6f50e9bd05df0440f5cbf5dfbc1badd