Impact
The Workspace Save API in Frappe allows any authenticated user to supply a workspace identifier and save changes without verifying ownership. This flaw enables an attacker to modify another user’s private workspace and embed malicious scripts that persist across sessions, combining broken access control with persistent script injection for unauthorized modification and potential arbitrary script execution.
Affected Systems
The issue impacts all installations of the frappe framework running any release prior to version 16.18.0. Only deployments upgraded to 16.18.0 or later have the fix applied.
Risk and Exploitability
The CVSS score of 5.1 denotes moderate severity and the EPSS score is not available, indicating no publicly reported exploit likelihood. The vulnerability is not listed in the CISA KEV catalog, so no known exploitation exists at present. However, because the attack requires authentication, an attacker with valid credentials can use the API to inject persistent scripts, making the attack vector predictable and potentially damaging to affected workspaces.
OpenCVE Enrichment