Frappe是印度Frappe公司开源的一款构建业务应用的开发框架。 Frappe 16.18.0之前版本存在安全漏洞,该漏洞源于Workspace Save API接受任意经身份验证用户的受控工作区标识符,但未强制实施工作区所有权,可能导致修改其他用户的私有工作区并注入持久脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47194 | 8.6 HIGH | Frappe: Host header poisoning can redirect magic login links to an attacker-controlled dom |
| CVE-2026-47765 | 7.1 HIGH | Frappe: Lack of Permissions in restore/bulk_restore |
| CVE-2026-49391 | 5.1 MEDIUM | Frappe: Stored XSS in Column Headers via Data Import |
No comments yet