Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ERPNext: Server-Side Template Injection leading to Remote Code Execution
Vulnerability Description
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code execution. This issue is fixed in versions 15.111.0 and 16.22.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
CWE-1336
Vulnerability Title
Frappe ERPNext 代码注入漏洞
Vulnerability Description
Frappe ERPNext是印度Frappe公司开源的一款企业资源计划管理软件。 Frappe ERPNext 15.111.0之前版本和16.0.0至16.22.0之前版本存在代码注入漏洞,该漏洞源于frappe.render_template被暴露且未强制restrict_globals,可能导致受限认证用户跨权限边界,造成服务器端模板注入和远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A