CVE Vulnerabilities

CVE-2020-35175

Published: Dec 11, 2020 | Modified: Jul 21, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

Affected Software

Name Vendor Start Version End Version
Frappe Frappe 12.0.0 (including) 12.12.0 (including)
Frappe Frappe 13.0.0-beta1 (including) 13.0.0-beta1 (including)
Frappe Frappe 13.0.0-beta2 (including) 13.0.0-beta2 (including)
Frappe Frappe 13.0.0-beta3 (including) 13.0.0-beta3 (including)
Frappe Frappe 13.0.0-beta4 (including) 13.0.0-beta4 (including)
Frappe Frappe 13.0.0-beta5 (including) 13.0.0-beta5 (including)
Frappe Frappe 13.0.0-beta6 (including) 13.0.0-beta6 (including)
Frappe Frappe 13.0.0-beta7 (including) 13.0.0-beta7 (including)
Frappe Frappe 13.0.0-beta8 (including) 13.0.0-beta8 (including)

References