Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, granting less privileged users permission to delete or clone a file. Versions 14.66.3 and 15.16.0 contain a patch for this issue. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-03-20T18:11:58.069Z
Updated: 2024-08-02T17:38:02.805Z
Reserved: 2024-02-19T14:43:05.994Z
Link: CVE-2024-27105
Vulnrichment
Updated: 2024-08-02T00:27:59.402Z
NVD
Status : Awaiting Analysis
Published: 2024-03-21T02:52:18.373
Modified: 2024-03-21T12:58:51.093
Link: CVE-2024-27105
Redhat
No data.