CVE-2020-35175: Medium severity frappe lms vulnerability
Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-35175?
CVE-2020-35175 is a vulnerability in Frappe Framework 12 and 13 that allows improper validation of the HTTP method for the frappe.client API.
What is the severity of CVE-2020-35175?
CVE-2020-35175 has a severity value of 5.3, which is considered medium.
How does CVE-2020-35175 affect Frappe Framework?
CVE-2020-35175 affects Frappe Framework versions 12 and 13, allowing improper validation of the HTTP method for the frappe.client API.
What is the fix for CVE-2020-35175?
To fix CVE-2020-35175, it is recommended to update Frappe Framework to a version that includes the relevant security patches.
Where can I find more information about CVE-2020-35175?
You can find more information about CVE-2020-35175 on the following references: [link1](https://github.com/frappe/frappe/pull/11228), [link2](https://github.com/frappe/frappe/pull/11237).