PT-2023-29860 · Frappe · Frappe

·

CVE-2023-46127

·

Published

2023-10-23

·

Updated

2023-10-31

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 14.49.0
Description Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection.
Recommendations For versions prior to 14.49.0, update to version 14.49.0 to resolve the issue. As a temporary workaround, consider restricting access to document creation for malicious users until the patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-46127
GHSA-J2W9-8XRR-7G98

Affected Products

Frappe