Impact
A flaw in Frappe HR allows an attacker to manipulate the employee argument passed to the get_attendance_requests function, causing the system to incorrectly grant access to attendance data. This results in unauthorized view or modification of sensitive employee records, and the vulnerability can be triggered from a remote location.
Affected Systems
The affected product is Frappe:HR version 16.15.0 and earlier. The failure occurs in the permission‑validation code within hrms/api/__init__.py for the get_expense_claims, get_shift_requests, and get_attendance_requests endpoints. No other versions are explicitly listed as affected.
Risk and Exploitability
The CVSS score of 5.3 represents a moderate risk; the EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote, involving crafted HTTP requests that supply a manipulated employee identifier. If exploited, an attacker can bypass authorization checks and access or alter attendance records for users they would not normally see.
OpenCVE Enrichment