CVE-2019-14966: SQL Injection
Published Aug 12, 2019
·Updated
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
Affected Software
1 affected component
Frappe frappe>=10.0.0<=12.0.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Aug 12, 2019
CVE Published
via MITRE·05:21 PM
Data Sourced
via MITRE·05:21 PM
Description
Frequently Asked Questions
1
What is the vulnerability identifier of this issue?
The vulnerability identifier of this issue is CVE-2019-14966.
2
What is the severity of CVE-2019-14966?
The severity of CVE-2019-14966 is high with a CVSS score of 8.8.
3
What is the affected software of CVE-2019-14966?
The affected software is Frappe Framework versions 10 through 12 before 12.0.4.
4
What is the nature of the vulnerability in CVE-2019-14966?
The vulnerability is an authenticated SQL injection.
5
How can I fix CVE-2019-14966?
To fix CVE-2019-14966, upgrade Frappe Framework to version 12.0.4 or later.