ERPNext
cpe:2.3:a:erpnext:erpnext:*:*:*:*:*:*:*
- < 16.9.1
A vulnerability in ERPNext versions prior to 16.9.1 allows users to modify data beyond their assigned roles due to inadequate authorization checks on certain endpoints. This issue has been addressed in version 16.9.1.
Exploitation of this vulnerability could lead to unauthorized data modifications, allowing users to change information they should not have access to.
Users are advised to upgrade to ERPNext version 16.9.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.