Frappe ERPNext before 16.34.1 Unauthorized Method Invocation
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3epss 0.2%
probabilidade de exploração
0.2%top 89% das CVEs
exploração observada
nãonenhuma fonte reporta
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and read their return values.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Produtos afetados
Frappe · ERPNextReferências
https://github.com/frappe/erpnexthttps://github.com/frappe/erpnext/blob/v16.34.0/erpnext/accounts/doctype/financial_report_template/financial_report_engine.py#L1166-L1171https://github.com/frappe/erpnext/blob/v16.34.0/erpnext/accounts/doctype/financial_report_template/financial_report_template.jsonhttps://github.com/frappe/erpnext/commit/7aad59b129711e9bba17b25665428d1fc57bf37chttps://github.com/frappe/erpnext/security/advisories/GHSA-794x-fhm7-58j7https://www.vulncheck.com/advisories/frappe-erpnext-before-16.34.1-unauthorized-method-invocation