Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Frappe HR has possibility of SQL Injection due to improper field sanitization
Vulnerability Description
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. Versions 15.54.0 and 14.38.1 contain a patch. No known workarounds are available.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Frappe HR SQL注入漏洞
Vulnerability Description
Frappe HR是Frappe开源的一个人力资源管理系统。 Frappe HR 15.54.0之前版本和14.38.1之前版本存在SQL注入漏洞,该漏洞源于对特定端点的特制请求可能导致SQL注入攻击,允许攻击者提取信息。
CVSS Information
N/A
Vulnerability Type
N/A