Schwachstellenklasse
Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.
Quellen
- https://github.com/frappe/frappe/commit/1ff64d4a67f9a6d8819ac059dc69f023fb9ea264
- https://github.com/frappe/frappe/commit/d3becf5672cbb5c7150447161941aeebeeb84ae8
- https://github.com/frappe/frappe/pull/38625
- https://github.com/frappe/frappe/pull/38626
- https://github.com/frappe/frappe/releases/tag/v15.106.0
- https://github.com/frappe/frappe/releases/tag/v16.16.0
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.