CVE-2022-23055

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:N
MendCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
frappeerpnext
11.0.4 ≤
𝑥
< 13.1.0
frappeerpnext
11.0.3:beta1
frappeerpnext
11.0.3:beta10
frappeerpnext
11.0.3:beta11
frappeerpnext
11.0.3:beta12
frappeerpnext
11.0.3:beta13
frappeerpnext
11.0.3:beta14
frappeerpnext
11.0.3:beta15
frappeerpnext
11.0.3:beta16
frappeerpnext
11.0.3:beta17
frappeerpnext
11.0.3:beta18
frappeerpnext
11.0.3:beta19
frappeerpnext
11.0.3:beta2
frappeerpnext
11.0.3:beta20
frappeerpnext
11.0.3:beta21
frappeerpnext
11.0.3:beta22
frappeerpnext
11.0.3:beta23
frappeerpnext
11.0.3:beta24
frappeerpnext
11.0.3:beta25
frappeerpnext
11.0.3:beta26
frappeerpnext
11.0.3:beta27
frappeerpnext
11.0.3:beta28
frappeerpnext
11.0.3:beta29
frappeerpnext
11.0.3:beta3
frappeerpnext
11.0.3:beta30
frappeerpnext
11.0.3:beta31
frappeerpnext
11.0.3:beta32
frappeerpnext
11.0.3:beta33
frappeerpnext
11.0.3:beta34
frappeerpnext
11.0.3:beta35
frappeerpnext
11.0.3:beta36
frappeerpnext
11.0.3:beta37
frappeerpnext
11.0.3:beta4
frappeerpnext
11.0.3:beta5
frappeerpnext
11.0.3:beta6
frappeerpnext
11.0.3:beta7
frappeerpnext
11.0.3:beta8
frappeerpnext
11.0.3:beta9
𝑥
= Vulnerable software versions