PT-2026-67849 · Frappe · Erpnext
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ERPNext versions prior to 15.115.0
ERPNext versions prior to 16.26.0
Description
Improper authorization occurs due to insufficient access control in the whitelisted API method
erpnext.crm.doctype.prospect.prospect.get opportunities(). This allows unauthorized access to data through the specified function.Recommendations
Update to version 15.115.0 or later.
Update to version 16.26.0 or later.
As a temporary workaround, restrict access to the
erpnext.crm.doctype.prospect.prospect.get opportunities() method.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Erpnext