Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-10-23T14:29:01.888Z

Updated: 2023-10-23T14:29:01.888Z

Reserved: 2023-10-16T17:51:35.572Z


Link: CVE-2023-46127

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-23T15:15:09.313

Modified: 2023-10-31T12:17:17.793


Link: CVE-2023-46127

JSON object: View

cve-icon Redhat Information

No data.

CWE