Frappe 是一个全栈 Web 应用框架。在版本 15.115.0 和 16.27.0 之前,frappe/website/doctype/personal_data_download_request/personal_data_download_request.py 文件中的公共请求数据 Web 表单以及 PersonalDataDownloadRequest 类,针对已注册和未注册的邮箱地址会返回可区分的响应结构,包括包含 user_name 字段及其持久化行为。远程攻击者可以通过比较这些响应来枚举已注册用户
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66001 | 8.5 HIGH | Frappe: Improper Authorization in OAuth2 Consent Endpoint |
| CVE-2026-62315 | 7.1 HIGH | Frappe: Mass assignment via set_value |
| CVE-2026-63654 | 6.9 MEDIUM | Frappe: Unauthenticated Workflow approval via confirm_action |
| CVE-2026-53569 | 5.3 MEDIUM | Frappe: Missing authorization in toggle_like and mark_as_seen |
No comments yet