Impact
Frappe, a full‑stack web framework, failed to re‑evaluate recipient permissions when generating document follow notifications. Users whose access had been revoked or reduced could still receive document data by email, enabling an unauthorized disclosure of confidential content. The weakness is an access control bypass (CWE‑863) that exposes sensitive information to unintended recipients.
Affected Systems
The issue affects the frappe:frappe application. It applies to all releases prior to 16.23.0 and 15.112.0; these specific versions contain the vulnerable logic. Use newer releases to eliminate the flaw.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity problem, and no EPSS score is available. Because the flaw exists only in the notification generation path, an attacker would need to have a legitimate user account, trigger a document follow event, or rely on an existing event, but could not directly code arbitrary requests. Consequently, the exploitability is limited and the impact is confined to recipients with revoked or reduced permissions. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment