CVE-2023-54345: Frappe Framework ERPNext 13.4.0 Remote Code Execution
Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame introspection. Attackers can create a server script via the /app/server-script endpoint and access the giframe attribute to traverse the call stack and invoke os.popen to execute system commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-54345?
CVE-2023-54345 is a critical vulnerability that allows remote code execution in Frappe Framework ERPNext 13.4.0.
How do I fix CVE-2023-54345?
To fix CVE-2023-54345, it is recommended to upgrade Frappe Framework ERPNext to the latest version that addresses this vulnerability.
Who is affected by CVE-2023-54345?
CVE-2023-54345 affects users of Frappe Framework ERPNext version 13.4.0 with the System Manager role.
What type of vulnerability is CVE-2023-54345?
CVE-2023-54345 is classified as a sandbox escape vulnerability that enables authenticated users to execute arbitrary code.
Can CVE-2023-54345 be exploited remotely?
Yes, CVE-2023-54345 can be exploited remotely by authenticated users, making it particularly dangerous.