CVE-2024-34074: Frappe vuilnerable to an open redirect on login page
Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34074?
CVE-2024-34074 is considered a high severity vulnerability due to its potential for phishing attacks.
How do I fix CVE-2024-34074?
To fix CVE-2024-34074, update to Frappe version 15.26.0 or 14.74.0 or later.
What types of software are affected by CVE-2024-34074?
CVE-2024-34074 affects Frappe versions prior to 15.26.0 and 14.74.0.
What is the main risk associated with CVE-2024-34074?
The main risk associated with CVE-2024-34074 is the potential for malicious actors to conduct phishing attacks through untrusted redirects.
Is CVE-2024-34074 a zero-day vulnerability?
CVE-2024-34074 is not a zero-day vulnerability as it has been publicly disclosed and fixed by the vendor.