← Back

CVE-2022-23055

nvd nist
Published: Jun 22, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:N
Exploitability: 8.0 / Impact: 4.9
Source: NVD

Description

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.

Affected (38)

Products: Frappe: Erpnext
1 product
Erpnext
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
Frappe
From 11.0.4 to 13.1.0
Version 11.0.3 beta10
Version 11.0.3 beta11
Version 11.0.3 beta12
Version 11.0.3 beta13
Version 11.0.3 beta14
Version 11.0.3 beta15
Version 11.0.3 beta16
Version 11.0.3 beta17
Version 11.0.3 beta18
Version 11.0.3 beta19
Version 11.0.3 beta1
Version 11.0.3 beta20
Version 11.0.3 beta21
Version 11.0.3 beta22
Version 11.0.3 beta23
Version 11.0.3 beta24
Version 11.0.3 beta25
Version 11.0.3 beta26
Version 11.0.3 beta27
Version 11.0.3 beta28
Version 11.0.3 beta29
Version 11.0.3 beta2
Version 11.0.3 beta30
Version 11.0.3 beta31
Version 11.0.3 beta32
Version 11.0.3 beta33
Version 11.0.3 beta34
Version 11.0.3 beta35
Version 11.0.3 beta36
Version 11.0.3 beta37
Version 11.0.3 beta3
Version 11.0.3 beta4
Version 11.0.3 beta5
Version 11.0.3 beta6
Version 11.0.3 beta7
Version 11.0.3 beta8
Version 11.0.3 beta9

References (6)

Source: vulnerabilitylab@mend.io
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory

Timeline

No history available yet.