First published: Mon Oct 23 2023(Updated: )
Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Frappe LMS | <14.49.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46127 is a vulnerability in Frappe that allows HTML injection by any Desk user.
The severity of CVE-2023-46127 is medium.
CVE-2023-46127 affects Frappe by allowing HTML injection by any Desk user.
Yes, CVE-2023-46127 has been patched in version 14.49.0 of Frappe.
To fix CVE-2023-46127, make sure to update Frappe to version 14.49.0 or higher.