VulnerabilityModified
CVE-2022-23055
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality.
MEDIUM 5.5EPSS 1.20%
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- frappe/erpnext
- Source
- vulnerabilitylab@mend.io
References
- https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L134Exploit, Third Party Advisory
- https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L155Exploit, Third Party Advisory
- https://www.mend.io/vulnerability-database/CVE-2022-23055Exploit, Patch, Third Party Advisory
- https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L134Exploit, Third Party Advisory
- https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L155Exploit, Third Party Advisory
- https://www.mend.io/vulnerability-database/CVE-2022-23055Exploit, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.