Frappe ERPNext 在 15.121.0 之前的版本以及 16.x 系列中 16.34.0 之前的版本,存在一个信息泄露漏洞,该漏洞出现在被白名单(whitelisted)的工时表(timesheet)接口中,这些接口未强制实施数据表类型(doctype)权限控制。经过身份验证的攻击者可以调用 、 和 接口,在缺乏适当授权检查的情况下,枚举并获取可计费工时记录,包括项目名称、计费金额和工作描述等敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet