CVE-2020-35175

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/12/2020
Last modified:
21/07/2021

Description

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:* 12.0.0 (including) 12.12.0 (including)
cpe:2.3:a:frappe:frappe:13.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:13.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:13.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:13.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:13.0.0:beta5:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:13.0.0:beta6:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:13.0.0:beta7:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:13.0.0:beta8:*:*:*:*:*:*