Frappe HR是Frappe开源的一个人力资源管理系统。 Frappe HR 15.58.1之前版本和16.4.1之前版本存在访问控制错误漏洞,该漏洞源于具有默认角色的经过身份验证的用户可利用某些API端点,可能导致访问未经授权的信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41320 | 6.5 MEDIUM | Frappe HR has possibility of SQL Injection due to improper field sanitization |
| CVE-2026-40889 | 6.5 MEDIUM | Frappe HR has Improper Access Control on Files |
No comments yet