Frappe 是一个全栈 Web 应用框架。14.96.9 及以下版本,以及 15.0.0 至 15.71.0 版本中存在一个不安全的端点参数,由于缺乏有效的验证,该参数易受基于报错的 SQL 注入攻击。攻击者可以借此窃取敏感信息,例如版本号等。该问题已在版本 14.96.10 和 15.72.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-66059 | 5.3 MEDIUM | Frappe: Field-level permission bypass via Document Follow |
| CVE-2026-66058 | 5.3 MEDIUM | Frappe: Unrestricted access to a Document Follow API |
| CVE-2026-66000 | 2.3 LOW | Frappe: Unrestricted access to Document Follow APIs |
No comments yet