SQL Injection Vulnerability in ERPNext Software by Frappe
CVE-2018-20061
What is CVE-2018-20061?
A SQL injection vulnerability exists in the ERPNext software, affecting versions 10.x and 11.x through 11.0.3-beta.29. The issue arises when a logged-in user can exploit this vulnerability without any special privileges. By invoking a JavaScript function that interacts with server-side Python functions, attackers can manipulate SQL queries to retrieve data from any table within the database. This security flaw is tied to specific API endpoints, including /api/resource/Item?fields= and functions like frappe.get_list and frappe.call. As many ERPNext installations permit user registration via the web, this presents a significant risk to unprotected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
