Frappe 是一个全栈 Web 应用框架。在 16.31.0 及更早版本中, 文件中受白名单保护的 端点因未限制仅允许 POST 方法,而接受其他安全的 HTTP 方法来执行改变工作流状态的操作。攻击者可以诱使已认证的受害者浏览器以受害者的权限提交审批操作。截至本次审查时,尚未发布任何修复该问题的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66001 | 8.5 HIGH | Frappe: Improper Authorization in OAuth2 Consent Endpoint |
| CVE-2026-62315 | 7.1 HIGH | Frappe: Mass assignment via set_value |
| CVE-2026-66002 | 6.9 MEDIUM | Frappe: User Enumeration via PDDR |
| CVE-2026-53569 | 5.3 MEDIUM | Frappe: Missing authorization in toggle_like and mark_as_seen |
No comments yet