CVE-2024-34074

MEDIUM

Frappe <15.26.0-14.74.0 - Open Redirect

Title source: llm
STIX 2.1

Description

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.

Scores

CVSS v3 6.1
EPSS 0.0027
EPSS Percentile 50.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
frappe/frappe < 14.74.0
Published May 14, 2024
Tracked Since Feb 18, 2026