Frappe Framework 的开发版本中, 接口存在一个授权缺陷,允许低权限用户通过提供原始模板字符串来渲染任意的 Jinja 模板。拥有任意文档打印权限的攻击者可以针对包括 表在内的无关数据表执行任意 SELECT 语句,从而读取其中的密码哈希值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet