Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Prior to commit 5d118a902872d7941f099ad1fb918e2421e79ccd, a user could inject HTML through SaaS signup inputs. The user who injected the unsafe HTML code would only affect themselves and would not affect other users. Commit 5d118a902872d7941f099ad1fb918e2421e79ccd patches this bug.
History

Wed, 23 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
Description Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Prior to commit 5d118a902872d7941f099ad1fb918e2421e79ccd, a user could inject HTML through SaaS signup inputs. The user who injected the unsafe HTML code would only affect themselves and would not affect other users. Commit 5d118a902872d7941f099ad1fb918e2421e79ccd patches this bug.
Title Frappe Press possible HTML injection through SaaS Signup inputs
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-23T15:45:12.348Z

Updated: 2024-10-23T16:27:13.106Z

Reserved: 2024-10-18T13:43:23.451Z

Link: CVE-2024-49751

cve-icon Vulnrichment

Updated: 2024-10-23T16:27:08.126Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-23T16:15:10.310

Modified: 2024-10-25T12:56:36.827

Link: CVE-2024-49751

cve-icon Redhat

No data.