SQL Injection Vulnerability Affects Frappe Users
CVE-2024-24813
What is CVE-2024-24813?
Frappe Framework, a comprehensive web application framework, has identified a vulnerability that permits SQL injection through a specific whitelisted method. This flaw allows attackers to access data beyond their permissions, leading to potential unauthorized information exposure. Users of versions prior to 14.64.0 and 15.0.0 are particularly affected, as these versions lack the necessary security measures to mitigate the risk. It's essential for users to upgrade to patched versions to safeguard against this vulnerability, as no alternative workarounds are available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
frappe < 14.64.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
