Frappe vulnerable to HTML injection by any Desk user
Vulnerability Description
Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-46127
Credits & Attribution
No credits recorded in the NVD database.
References
More from frappe
View All →Affected Vendor
frappe
View all reports →