Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-10-23T14:29:01.888Z

Updated: 2024-09-11T15:23:48.149Z

Reserved: 2023-10-16T17:51:35.572Z

Link: CVE-2023-46127

cve-icon Vulnrichment

Updated: 2024-08-02T20:37:39.327Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-23T15:15:09.313

Modified: 2023-10-31T12:17:17.793

Link: CVE-2023-46127

cve-icon Redhat

No data.