High severity7.5NVD Advisory· Published Mar 18, 2020· Updated Jun 17, 2026
CVE-2019-20529
CVE-2019-20529
Description
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Frappe/Frappedescription
Patches
Vulnerability mechanics
References
2- github.com/frappe/frappe/pull/8884nvdThird Party Advisory
- github.com/frappe/frappe/pull/8885nvdThird Party Advisory
News mentions
0No linked articles in our index yet.