← voltar
CVE-2025-68929

Frappe may be vulnerable remote code execution due to server-side template injection

CVSS 9.1 CRITICALEPSS 0.4%CWE-1336
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Produtos afetados
frappe · frappe

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →