Vulnerabilities
Vulnerable Software
Frappe:  Security Vulnerabilities
In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.
CVSS Score
7.5
EPSS Score
0.003
Published
2020-12-11
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVSS Score
6.4
EPSS Score
0.017
Published
2020-08-10
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
CVSS Score
7.4
EPSS Score
0.003
Published
2020-03-19
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
CVSS Score
7.4
EPSS Score
0.003
Published
2020-03-19
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
CVSS Score
7.4
EPSS Score
0.003
Published
2020-03-19
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
CVSS Score
7.4
EPSS Score
0.003
Published
2020-03-19
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
CVSS Score
7.4
EPSS Score
0.003
Published
2020-03-19
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
CVSS Score
7.4
EPSS Score
0.003
Published
2020-03-19
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
CVSS Score
7.4
EPSS Score
0.003
Published
2020-03-19
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
CVSS Score
7.4
EPSS Score
0.003
Published
2020-03-19


Contact Us

Shodan ® - All rights reserved