5.5

CVE-2022-23055

Exploit
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FrappeErpnext Version >= 11.0.4 < 13.1.0
FrappeErpnext Version11.0.3 Updatebeta1
FrappeErpnext Version11.0.3 Updatebeta10
FrappeErpnext Version11.0.3 Updatebeta11
FrappeErpnext Version11.0.3 Updatebeta12
FrappeErpnext Version11.0.3 Updatebeta13
FrappeErpnext Version11.0.3 Updatebeta14
FrappeErpnext Version11.0.3 Updatebeta15
FrappeErpnext Version11.0.3 Updatebeta16
FrappeErpnext Version11.0.3 Updatebeta17
FrappeErpnext Version11.0.3 Updatebeta18
FrappeErpnext Version11.0.3 Updatebeta19
FrappeErpnext Version11.0.3 Updatebeta2
FrappeErpnext Version11.0.3 Updatebeta20
FrappeErpnext Version11.0.3 Updatebeta21
FrappeErpnext Version11.0.3 Updatebeta22
FrappeErpnext Version11.0.3 Updatebeta23
FrappeErpnext Version11.0.3 Updatebeta24
FrappeErpnext Version11.0.3 Updatebeta25
FrappeErpnext Version11.0.3 Updatebeta26
FrappeErpnext Version11.0.3 Updatebeta27
FrappeErpnext Version11.0.3 Updatebeta28
FrappeErpnext Version11.0.3 Updatebeta29
FrappeErpnext Version11.0.3 Updatebeta3
FrappeErpnext Version11.0.3 Updatebeta30
FrappeErpnext Version11.0.3 Updatebeta31
FrappeErpnext Version11.0.3 Updatebeta32
FrappeErpnext Version11.0.3 Updatebeta33
FrappeErpnext Version11.0.3 Updatebeta34
FrappeErpnext Version11.0.3 Updatebeta35
FrappeErpnext Version11.0.3 Updatebeta36
FrappeErpnext Version11.0.3 Updatebeta37
FrappeErpnext Version11.0.3 Updatebeta4
FrappeErpnext Version11.0.3 Updatebeta5
FrappeErpnext Version11.0.3 Updatebeta6
FrappeErpnext Version11.0.3 Updatebeta7
FrappeErpnext Version11.0.3 Updatebeta8
FrappeErpnext Version11.0.3 Updatebeta9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.53
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 8 4.9
AV:N/AC:L/Au:S/C:P/I:P/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.