Description
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.
Problem types
CWE-862: Missing Authorization
CWE-306: Missing Authentication for Critical Function
CWE-284: Improper Access Control
Product status
< 15.98.1
References
github.com/...rpnext/security/advisories/GHSA-wpfx-jw7g-7f83
github.com/...ommit/78fc9424d9085c2eafe1211931e22d7044f85fc7