Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to create or modify a Terms and Conditions document can inject arbitrary Jinja expressions into the terms field, resulting in server-side code execution within a restricted but still unsafe context. This vulnerability can be used to leak database information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ERPNext 安全漏洞
Vulnerability Description
ERPNext是印度ERPNext公司的一套开源的企业资源计划解决方案。 ERPNext 15.89.0及之前版本存在安全漏洞,该漏洞源于get_terms_and_conditions方法存在服务器端模板注入,可能导致服务器端代码执行。
CVSS Information
N/A
Vulnerability Type
N/A