CVE-2022-23055 Information
Jun 28, 2022
cve
Description
In ERPNext versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to and of other users.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Reference
https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L134https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L155 https://www.mend.io/vulnerability-database/CVE-2022-23055
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: