CVE-2017-1000120: SQL Injection
Published Oct 4, 2017
·Updated
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.getusers allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.
Affected Software
1 affected component
Frappe frappe<=7.1.27
Event History
Oct 4, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000120?
CVE-2017-1000120 has a medium severity due to its potential for SQL injection by remote authenticated users.
2
How do I fix CVE-2017-1000120?
To fix CVE-2017-1000120, upgrade Frappe to version 7.1.28 or later, where the vulnerability has been addressed.
3
Who is affected by CVE-2017-1000120?
Any remote authenticated user of Frappe versions 7.1.27 and below can be affected by CVE-2017-1000120.
4
What kind of attack can be performed using CVE-2017-1000120?
CVE-2017-1000120 allows attackers to execute arbitrary SQL commands through the fields parameter.
5
Is CVE-2017-1000120 a local or remote vulnerability?
CVE-2017-1000120 is a remote vulnerability that requires authenticated access to the affected system.