Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authentica…
Medium CVSS 6.5
Summary
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/frappe/erpnext/commit/c656497aac76af82eea028e3e8cb8d5380385f0f
- https://github.com/frappe/erpnext/commit/d5df40986d72a55d414ddaf4d382883f9df31e41
- https://github.com/frappe/erpnext/pull/58576
- https://github.com/frappe/erpnext/security/advisories/GHSA-9vph-hqmm-g7hq
- https://www.vulncheck.com/advisories/frappe-erpnext-before-15.121.0-and-16.34.0-missing-authorization-in-timesheet-endpoints
Timeline
- nvd_ingest NVD