Frappe vulnerable to information disclosure leading to account takeover
Package
Affected versions
< 14.89.0
>= 15.0.0, < 15.51.0
Patched versions
14.89.0
15.51.0
Description
Published by the National Vulnerability Database
Mar 25, 2025
Published to the GitHub Advisory Database
Mar 25, 2025
Reviewed
Mar 25, 2025
Last updated
Mar 30, 2025
Impact
Making crafted requests could lead to information disclosure that could further lead to account takeover.
Workarounds
There's no workaround to fix this without upgrading.
Credits
Thanks to Thanh of Calif.io for reporting the issue
References