Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correctly validate the information injected by the user in the import_file parameter.
References
Link Resource
https://fluidattacks.com/advisories/kiniza/ Exploit Third Party Advisory
https://github.com/frappe/frappe/ Product
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2022-11-25T00:00:00

Updated: 2022-11-25T00:00:00

Reserved: 2022-09-28T00:00:00


Link: CVE-2022-41712

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-11-25T18:15:11.110

Modified: 2022-11-30T16:01:41.073


Link: CVE-2022-41712

JSON object: View

cve-icon Redhat Information

No data.

CWE