7.1
CVE-2026-94113
- EPSS 0.24%
- Veröffentlicht 20.09.2026 11:56:08
- Zuletzt bearbeitet 21.09.2026 17:19:19
- Erkennungen
Frappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet Endpoints
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to enumerate and retrieve billable time logs including project names, billing amounts, and work descriptions without proper authorization checks.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFrappe
≫
Produkt
ERPNext
Default Statusunaffected
Version
0
Version <
15.121.0
Status
affected
Version
16.0.0
Version <
16.34.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.157 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 7.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/frappe/erpnext/security/advisories/GHSA-9vph-hqmm-g7hq
https://github.com/frappe/erpnext/commit/c656497aac76af82eea028e3e8cb8d5380385f0f
https://github.com/frappe/erpnext/commit/d5df40986d72a55d414ddaf4d382883f9df31e41
https://github.com/frappe/erpnext/pull/58576
https://www.vulncheck.com/advisories/frappe-erpnext-before-15.121.0-and-16.34.0-missing-authorization-in-timesheet-endpoints