Lucene search

K
osvGoogleOSV:CVE-2020-6145
HistoryAug 10, 2020 - 2:15 p.m.

CVE-2020-6145

2020-08-1014:15:13
Google
osv.dev
5

7.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

29.0%

An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

7.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

29.0%

Related for OSV:CVE-2020-6145