Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-11T15:23:48.149Z
Reserved: 2023-10-16T17:51:35.572Z
Link: CVE-2023-46127
Updated: 2024-08-02T20:37:39.327Z
Status : Modified
Published: 2023-10-23T15:15:09.313
Modified: 2024-11-21T08:27:56.190
Link: CVE-2023-46127
No data.
OpenCVE Enrichment
No data.
Weaknesses