CVE-2024-24813

CVSS V2 None CVSS V3 None
Description
Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular whitelisted method can result in access to data which the user doesn't have permission to access. Versions 14.64.0 and 15.0.0 contain a patch for this issue. No known workarounds are available.
Overview
  • CVE ID
  • CVE-2024-24813
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-20T18:11:34.165Z
  • Last Modified Date
  • 2024-03-20T18:11:34.165Z
References
Reference URL Reference Tags
https://github.com/frappe/frappe/security/advisories/GHSA-fxfv-7gwx-54jh x_refsource_CONFIRM
History
Created Old Value New Value Data Type Notes
2024-06-26 04:27:35 Added to TrackCVE