SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-23055

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality.

MEDIUM 5.5EPSS 1.20%

Does this matter?

Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.

Description

In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.

CVSS 2.0
5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
EPSS
1.20% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
frappe/erpnext
Source
vulnerabilitylab@mend.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.