Home
HIGH: 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L >= 15.0.0, < 15.86.0
affected
< 14.99.2
affected
Description
Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of validation of parameters. Some information like version could be retrieved. This vulnerability is fixed in 15.86.0 and 14.99.2.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
< 14.99.2
References
github.com/...frappe/security/advisories/GHSA-mp93-8vxr-hqq9
github.com/...ommit/984c641bff9539b6126a01146096f133db6a955b