Schwachstellenklasse
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15.110.0.
Quellen
- https://github.com/frappe/frappe/commit/4bf27db101c34bd542a760290fc0775efa5cd0e4
- https://github.com/frappe/frappe/commit/b1c86042e6f85986f35365c80bb1d102ff1cd0e4
- https://github.com/frappe/frappe/commit/fee1af6d89910f6b174fd094184060aeb641d07d
- https://github.com/frappe/frappe/pull/39407
- https://github.com/frappe/frappe/pull/39550
- https://github.com/frappe/frappe/pull/39553
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.