CVE-2023-41328
Possibility limited SQL injection due to insufficient validation in Frappe
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which could allow a malicious actor to access sensitive information. This issue has been addressed in versions 13.46.1 and 14.20.0. Users are advised to upgrade. There's no workaround to fix this without upgrading.
Frappe es un framework web de código bajo escrito en Python y Javascript. Se ha identificado una vulnerabilidad de inyección SQL en Frappe Framework que podría permitir a un actor malintencionado acceder a información confidencial. Este problema se ha solucionado en las versiones 13.46.1 y 14.20.0. Se recomienda a los usuarios que actualicen. No hay ningún workaround para solucionar esto sin actualizar.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-08-28 CVE Reserved
- 2023-09-06 CVE Published
- 2024-09-26 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/frappe/frappe/releases/tag/v13.46.1 | Third Party Advisory | |
https://github.com/frappe/frappe/releases/tag/v14.20.0 | Third Party Advisory | |
https://github.com/frappe/frappe/security/advisories/GHSA-53wh-f67g-9679 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Frappe Search vendor "Frappe" | Frappe Search vendor "Frappe" for product "Frappe" | < 13.46.1 Search vendor "Frappe" for product "Frappe" and version " < 13.46.1" | - |
Affected
| ||||||
Frappe Search vendor "Frappe" | Frappe Search vendor "Frappe" for product "Frappe" | >= 14.0.0 < 14.20.0 Search vendor "Frappe" for product "Frappe" and version " >= 14.0.0 < 14.20.0" | - |
Affected
|