CyberRota Analysis
AI-GeneratedFrappe's web application framework prior to version 16.19.0 is vulnerable to an authorization bypass through the update_page endpoint in Workspace, allowing unauthorized users to edit public workspaces without proper checks. This could lead to unauthorized modifications of workspace content, potentially compromising data integrity and security. Organizations using affected versions should prioritize upgrading to 16.19.0 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0.