Frappe
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*
- < 16.15.0
- < 15.105.0
A critical arbitrary file read vulnerability via path traversal has been identified in Frappe Framework versions prior to 15.105.0 and 16.15.0. This vulnerability allows for unauthorized access to files on the server.
Exploitation of this vulnerability could lead to unauthorized reading of files on the server, potentially allowing attackers to access sensitive information.
Users are advised to upgrade to Frappe Framework versions 16.15.0, 15.105.0 or above.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.