CVE-2023-46127

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
23/10/2023
Last modified:
31/10/2023

Description

Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:* 14.49.0 (excluding)