PT-2026-95969 · Frappe · Erpnext
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Frappe ERPNext versions prior to 15.121.0
Frappe ERPNext versions 16.x prior to 16.34.0
Description
An information disclosure issue exists in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call the
get projectwise timesheet data, get timesheet detail rate, and get timesheet endpoints to enumerate and retrieve billable time logs, including project names, billing amounts, and work descriptions, without proper authorization checks.Recommendations
Update to version 15.121.0 or later.
Update to version 16.34.0 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Erpnext