Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authentica…
中危 CVSS 6.5
摘要
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/frappe/erpnext/commit/c656497aac76af82eea028e3e8cb8d5380385f0f
- https://github.com/frappe/erpnext/commit/d5df40986d72a55d414ddaf4d382883f9df31e41
- https://github.com/frappe/erpnext/pull/58576
- https://github.com/frappe/erpnext/security/advisories/GHSA-9vph-hqmm-g7hq
- https://www.vulncheck.com/advisories/frappe-erpnext-before-15.121.0-and-16.34.0-missing-authorization-in-timesheet-endpoints
时间线
- nvd_ingest NVD