CVE-2020-35175
11.12.2020, 23:15
Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.Enginsight
Vendor | Product | Version |
---|---|---|
frappe | frappe | 12.0.0 ≤ 𝑥 ≤ 12.12.0 |
frappe | frappe | 13.0.0:beta1 |
frappe | frappe | 13.0.0:beta2 |
frappe | frappe | 13.0.0:beta3 |
frappe | frappe | 13.0.0:beta4 |
frappe | frappe | 13.0.0:beta5 |
frappe | frappe | 13.0.0:beta6 |
frappe | frappe | 13.0.0:beta7 |
frappe | frappe | 13.0.0:beta8 |
𝑥
= Vulnerable software versions