Frappe
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*
- < 14.89.0
- < 15.51.0
A vulnerability in the Frappe web application framework prior to versions 14.89.0 and 15.51.0 allows crafted requests to cause information disclosure, potentially leading to account takeover. The issue has been fixed in versions 14.89.0 and 15.51.0. There is no workaround available other than upgrading.
Exploitation of this vulnerability could result in unauthorized account access.
Users should upgrade to Frappe versions 14.89.0 or 15.51.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.