6.9
CVE-2026-66002
- EPSS -
- Veröffentlicht 20.08.2026 18:29:40
- Zuletzt bearbeitet 20.08.2026 19:16:58
- CVE-Watchlists
- Unerledigt
Frappe: User Enumeration via PDDR
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response shapes for registered and unregistered email addresses, including the user_name field and persistence behavior. A remote attacker can compare the responses to enumerate registered users. This issue is fixed in versions 15.115.0 and 16.27.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerfrappe
≫
Produkt
frappe
Version
< 15.115.0
Status
affected
Version
>= 16.0.0-beta.1, < 16.27.0
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-204 Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
https://github.com/frappe/frappe/security/advisories/GHSA-c2xv-c53h-qvr5
https://github.com/frappe/frappe/pull/40787
https://github.com/frappe/frappe/pull/40814
https://github.com/frappe/frappe/pull/40815
https://github.com/frappe/frappe/commit/30fe0b4118ff94c95c239dce4bc74ec4ca10a827
https://github.com/frappe/frappe/commit/47a396ec59f5362029feb349eb2b9d10a21afcf8
https://github.com/frappe/frappe/commit/4b32a4e0072e61ce0abcb0d09cfd1f14724fe896
https://github.com/frappe/frappe/releases/tag/v15.115.0
https://github.com/frappe/frappe/releases/tag/v16.27.0