Frappe 是一个全栈 Web 应用框架。在版本 15.114.0 和 16.26.0 之前,frappe/integrations/oauth2.py 中的 approve(批准)和 authorize(授权)函数存在安全缺陷:允许 OAuth2 同意流程在以下不安全条件下继续执行: 1. 未限制 approve 操作必须通过 HTTP POST 方法发起; 2. frappe/templates/includes/oauth_confirmation.html 模板中未包含 CSRF 令牌(csrf_toke
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-62315 | 7.1 HIGH | Frappe: Mass assignment via set_value |
| CVE-2026-66002 | 6.9 MEDIUM | Frappe: User Enumeration via PDDR |
| CVE-2026-63654 | 6.9 MEDIUM | Frappe: Unauthenticated Workflow approval via confirm_action |
| CVE-2026-53569 | 5.3 MEDIUM | Frappe: Missing authorization in toggle_like and mark_as_seen |
No comments yet