šŸ“Œ Pinned

  • SQL Injection, Insufficient ACLs in Frappe Framework, Frappe Learning & Frappe Press

    In this long-due post I describe some security vulnerabilities I found in Frappe Framework1, Frappe Learning2 and Frappe press3. While I did my best responsibly disclosing these vulnerabilities, the vendor was not very helpful in the process and did not communicate properly once the findings were sent their way.

    1. https://github.com/frappe/frappeĀ 

    2. https://github.com/frappe/lmsĀ 

    3. https://github.com/frappe/pressĀ 

Previous Posts