Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-23T14:29:01.888Z
Updated: 2024-09-11T15:23:48.149Z
Reserved: 2023-10-16T17:51:35.572Z
Link: CVE-2023-46127
Vulnrichment
Updated: 2024-08-02T20:37:39.327Z
NVD
Status : Modified
Published: 2023-10-23T15:15:09.313
Modified: 2024-11-21T08:27:56.190
Link: CVE-2023-46127
Redhat
No data.