CVE-2023-46127

CVSS V2 None CVSS V3 None
Description
Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.
Overview
  • CVE ID
  • CVE-2023-46127
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-10-23T14:29:01.888Z
  • Last Modified Date
  • 2023-10-23T14:29:01.888Z
History
Created Old Value New Value Data Type Notes
2024-06-24 22:39:56 Added to TrackCVE