CVE Vulnerabilities

CVE-2020-35175

Published: Dec 11, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

Affected Software

NameVendorStart VersionEnd Version
FrappeFrappe12.0.0 (including)12.12.0 (including)
FrappeFrappe13.0.0-beta1 (including)13.0.0-beta1 (including)
FrappeFrappe13.0.0-beta2 (including)13.0.0-beta2 (including)
FrappeFrappe13.0.0-beta3 (including)13.0.0-beta3 (including)
FrappeFrappe13.0.0-beta4 (including)13.0.0-beta4 (including)
FrappeFrappe13.0.0-beta5 (including)13.0.0-beta5 (including)
FrappeFrappe13.0.0-beta6 (including)13.0.0-beta6 (including)
FrappeFrappe13.0.0-beta7 (including)13.0.0-beta7 (including)
FrappeFrappe13.0.0-beta8 (including)13.0.0-beta8 (including)

References