Impact
The vulnerability lies in a missing authorization check for the get_linked_docs_of_document endpoint in Frappe CRM. Users who are already authenticated can request linked documents for records they should not otherwise have visibility into, such as leads, deals, comments or user profiles. By enumerating these records the attacker can retrieve sensitive details such as call log phone numbers, associated organizations, and notification text, potentially compromising privacy and business data.
Affected Systems
Frappe CRM versions 1.49.0 through 1.87.0 are affected. The issue is present in the crm.api.doc module of these releases.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. Because the vulnerability is only exploitable by authenticated users, the attack vector is internal or privileged accounts; external unauthenticated attackers cannot exploit it. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. Nonetheless, any organization that relies on Frappe CRM for managing sensitive customer data should treat this as a significant privacy risk and consider it for prioritization.
OpenCVE Enrichment