← Back

CVE-2018-20061

nvd nist
Published: Dec 11, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a JavaScript function that calls a server-side Python function with carefully chosen arguments, a SQL attack can be carried out which allows SQL queries to be constructed to return any columns from any tables in the database. This is related to /api/resource/Item?fields= URIs, frappe.get_list, and frappe.call.

Affected (30)

Products: Frappe: Erpnext
1 product
Erpnext
Configuration A
30 vulnerable
Vulnerable SoftwareAffected Versions
Frappe
From 10.0.0 to 10.1.76
From 11.0.0 to 11.0.3
Version 11.0.3 beta10
Version 11.0.3 beta11
Version 11.0.3 beta12
Version 11.0.3 beta13
Version 11.0.3 beta14
Version 11.0.3 beta15
Version 11.0.3 beta16
Version 11.0.3 beta17
Version 11.0.3 beta18
Version 11.0.3 beta19
Version 11.0.3 beta20
Version 11.0.3 beta21
Version 11.0.3 beta22
Version 11.0.3 beta23
Version 11.0.3 beta24
Version 11.0.3 beta25
Version 11.0.3 beta26
Version 11.0.3 beta27
Version 11.0.3 beta28
Version 11.0.3 beta29
Version 11.0.3 beta2
Version 11.0.3 beta3
Version 11.0.3 beta4
Version 11.0.3 beta5
Version 11.0.3 beta6
Version 11.0.3 beta7
Version 11.0.3 beta8
Version 11.0.3 beta9

References (2)

Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.