First published: Wed Sep 06 2023(Updated: )
Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which could allow a malicious actor to access sensitive information. This issue has been addressed in versions 13.46.1 and 14.20.0. Users are advised to upgrade. There's no workaround to fix this without upgrading.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Frappe LMS | <13.46.1 | |
Frappe LMS | >=14.0.0<14.20.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41328 is a SQL Injection vulnerability in the Frappe Framework that could allow an attacker to access sensitive information.
CVE-2023-41328 could potentially allow a malicious actor to access sensitive information through SQL Injection.
Versions up to 13.46.1 and versions between 14.0.0 and 14.20.0 of Frappe Framework are affected by CVE-2023-41328.
Users should upgrade their Frappe Framework to versions 13.46.1 or 14.20.0, which address the CVE-2023-41328 vulnerability.
More information about CVE-2023-41328 can be found in the references provided: [link1], [link2], [link3].