CVE-2020-6145: SQL Injection
Published Aug 10, 2020
·Updated
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
1 affected component
Frappe ERPNext=11.1.38
Event History
Aug 10, 2020
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-6145?
CVE-2020-6145 is an SQL injection vulnerability in the frappe.desk.reportview.get functionality of ERPNext 11.1.38.
2
What is the severity of CVE-2020-6145?
The severity of CVE-2020-6145 is high, with a severity value of 8.8.
3
How does CVE-2020-6145 work?
CVE-2020-6145 can be exploited by sending a specially crafted HTTP request, which can cause an SQL injection.
4
Which software versions are affected by CVE-2020-6145?
Version 11.1.38 of Frappe ERPNext is affected by CVE-2020-6145.
5
Is authentication required to exploit CVE-2020-6145?
Yes, an attacker needs to make an authenticated HTTP request to trigger the vulnerability.