VYPR
Unrated severityNVD Advisory· Published Oct 23, 2023· Updated Sep 11, 2024

Frappe vulnerable to HTML injection by any Desk user

CVE-2023-46127

Description

Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.