First published: Mon Aug 12 2019(Updated: )
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Frappe Frappe | >=10.0.0<12.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14965 is a server-side template injection (SSTI) vulnerability in Frappe Framework versions 10 through 12 before 12.0.4.
CVE-2019-14965 has a severity rating of 9.8 (Critical).
CVE-2019-14965 affects Frappe Framework versions 10 through 12 before 12.0.4.
To fix CVE-2019-14965, you should update Frappe Framework to version 12.0.4 or later.
The CWE ID for CVE-2019-14965 is CWE-94 (Improper Control of Generation of Code).