Lucene search

K
cvelistGitHub_MCVELIST:CVE-2024-34074
HistoryMay 09, 2024 - 2:25 p.m.

CVE-2024-34074 Frappe vuilnerable to an open redirect on login page

2024-05-0914:25:25
CWE-601
GitHub_M
www.cve.org
1
frappe
open redirect
vulnerability
fixed
phishing
web application framework

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0

Percentile

15.5%

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.

CNA Affected

[
  {
    "vendor": "frappe",
    "product": "frappe",
    "versions": [
      {
        "version": ">= 15.0.0, <= 15.25.0",
        "status": "affected"
      },
      {
        "version": "<= 14.73.0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0

Percentile

15.5%

Related for CVELIST:CVE-2024-34074