PT-2026-97358 · Frappe · Erpnext
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Frappe ERPNext versions prior to 16.34.1
Description
Accounts Managers can invoke non-whitelisted internal server-side methods and read their return values. This occurs because the software fails to validate that the
calculation formula values within the Financial Report Template reference whitelisted methods before they are passed to the frappe.call() function. An attacker can supply arbitrary dotted Python paths to execute these unauthorized methods.Recommendations
Update to version 16.34.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Erpnext