Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerabi…
Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which …
Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correc…
A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templa…
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is pla…
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker…
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low priv…
Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.
In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause …
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (…
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "…
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, man…
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injectio…
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.