First published: Mon Aug 10 2020(Updated: )
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Frappe ERPNext | =11.1.38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6145 is an SQL injection vulnerability in the frappe.desk.reportview.get functionality of ERPNext 11.1.38.
The severity of CVE-2020-6145 is high, with a severity value of 8.8.
CVE-2020-6145 can be exploited by sending a specially crafted HTTP request, which can cause an SQL injection.
Version 11.1.38 of Frappe ERPNext is affected by CVE-2020-6145.
Yes, an attacker needs to make an authenticated HTTP request to trigger the vulnerability.