Description
Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-11T15:23:48.149Z
Reserved: 2023-10-16T17:51:35.572Z
Link: CVE-2023-46127
Updated: 2024-08-02T20:37:39.327Z
Status : Modified
Published: 2023-10-23T15:15:09.313
Modified: 2024-11-21T08:27:56.190
Link: CVE-2023-46127
No data.
OpenCVE Enrichment
No data.
Weaknesses