Back to search
CVE-2022-23055
Published: Jun 22, 2022
Modified: Sep 16, 2024
PUBLISHED
Description
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.
| Vendor | Product | Versions |
|---|---|---|
frappe | frappe | affected v11.0.3-beta.1 - < unspecifiedaffected unspecified - <= v13.14.1 |
Weaknesses (CWE)
References
https://www.mend.io/vulnerability-database/CVE-2022-23055
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now