Medium severity5.3NVD Advisory· Published Dec 11, 2020· Updated Jun 17, 2026
CVE-2020-35175
CVE-2020-35175
Description
Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*range: >=12.0.0,<=12.12.0
- cpe:2.3:a:frappe:frappe:13.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:frappe:frappe:13.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:frappe:frappe:13.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:frappe:frappe:13.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:frappe:frappe:13.0.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:frappe:frappe:13.0.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:frappe:frappe:13.0.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:frappe:frappe:13.0.0:beta8:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
2- github.com/frappe/frappe/pull/11237nvdPatchThird Party Advisory
- github.com/frappe/frappe/pull/11228nvdThird Party Advisory
News mentions
0No linked articles in our index yet.