Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix
Vulnerability Description
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope. This issue is fixed in versions 15.111.0 and 16.22.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
Frappe erpnext 代码注入漏洞
Vulnerability Description
Frappe erpnext是印度Frappe公司开源的一套企业资源规划系统。 Frappe erpnext 15.111.0版本之前和16.0.0至16.22.0之前版本存在安全漏洞,该漏洞源于通过配置字段触发服务器端模板注入,可能导致经身份验证的用户泄露其正常权限范围之外的数据。
CVSS Information
N/A
Vulnerability Type
N/A