在 Frappe HR 16.15.0 及之前版本中发现了一个安全漏洞。该漏洞影响“权限验证”组件中 文件内的 、 和 函数。由于对 参数的不当处理,导致授权检查出现错误,从而可能引发越权访问。攻击者可在远程利用此漏洞。厂商回复称:“此问题已由其他人员报告,基于该报告,我们已经修复了该问题。”
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet