Lucene search

K
cve[email protected]CVE-2024-34074
HistoryMay 14, 2024 - 3:38 p.m.

CVE-2024-34074

2024-05-1415:38:27
CWE-601
web.nvd.nist.gov
2
frappe web app
unauthorized redirects
phishing vulnerability
nvd

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.

Affected configurations

Vulners
Node
frappefrappeRange15.0.015.25.0
OR
frappefrappeRange14.73.0
VendorProductVersionCPE
frappefrappe*cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*
frappefrappe*cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "frappe",
    "product": "frappe",
    "versions": [
      {
        "version": ">= 15.0.0, <= 15.25.0",
        "status": "affected"
      },
      {
        "version": "<= 14.73.0",
        "status": "affected"
      }
    ]
  }
]

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

Related for CVE-2024-34074