VYPR

Frappe

by Frappe

pypi: frappe

Source repositories

CVEs (108)

  • CVE-2022-23057MedJun 22, 2022
    risk 0.00cvss 5.4epss 0.01

    In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.

  • CVE-2020-35175MedDec 11, 2020
    risk 0.00cvss 5.3epss 0.01

    Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

  • CVE-2020-27508HigDec 11, 2020
    risk 0.00cvss 7.5epss 0.01

    In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.

  • CVE-2019-20529HigMar 18, 2020
    risk 0.00cvss 7.5epss 0.01

    In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.

  • CVE-2019-15700MedAug 27, 2019
    risk 0.00cvss 6.1epss 0.01

    public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.

  • CVE-2019-14967MedAug 12, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.

  • CVE-2019-14966HigAug 12, 2019
    risk 0.00cvss 8.8epss 0.01

    An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.

  • CVE-2019-14965CriAug 12, 2019
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.

Page 6 of 6