Vulnerability Spotlight: TALOS-2018-0560 -ERPNext SQL Injection Vulnerabilities
Publish Time: 06 Sep, 2018

Overview

Talos is disclosing multiple SQL injection vulnerabilities in the Frappe ERPNext Version 10.1.6 application. Frappe ERPNext is an open-source enterprise resource planning (ERP) cloud application. These vulnerabilities enable an attacker to bypass authentication and get unauthenticated access to sensitive data. An attacker can use a normal web browser to trigger these vulnerabilities - no special tools are required.

<<READ MORE>>


I’d like Alerts: