漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filter
Vulnerability Description
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_details and get_last_sales_amt, allowing an authenticated user to extract sensitive information and manipulate database queries. This issue is fixed in versions 15.116.0 and 16.23.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Frappe ERPNext SQL注入漏洞
Vulnerability Description
Frappe ERPNext是印度Frappe公司开源的一款企业资源计划管理软件。 Frappe ERPNext 15.116.0之前版本和16.23.0之前版本存在SQL注入漏洞,该漏洞源于inactive_customers.py文件接受未经验证的doctype过滤器并将其插入get_sales_details和get_last_sales_amt的原始SQL查询中,可能导致经过身份验证的用户提取敏感信息并操纵数据库查询。
CVSS Information
N/A
Vulnerability Type
N/A