CVE-2022-23055: ERPNext - Improper user access conrol
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23055?
The severity of CVE-2022-23055 is medium (5.4).
How does CVE-2022-23055 affect ERPNext versions?
CVE-2022-23055 affects ERPNext versions v11.0.0-beta through v13.0.2.
What is the vulnerability in ERPNext versions v11.0.0-beta through v13.0.2?
The vulnerability in ERPNext versions v11.0.0-beta through v13.0.2 is Missing Authorization in the chat rooms functionality.
How can a low privileged attacker exploit CVE-2022-23055?
A low privileged attacker can send direct messages or group messages to any member or group, impersonating themselves as the administrator and read chat messages.
Where can I find more information about CVE-2022-23055?
You can find more information about CVE-2022-23055 at the following references: [link1](https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L134), [link2](https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L155), [link3](https://www.mend.io/vulnerability-database/CVE-2022-23055).