CVE-2022-23055 Details
Description
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L134 | CVE | ExploitThird Party Advisory |
| https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L155 | CVE | ExploitThird Party Advisory |
| https://www.mend.io/vulnerability-database/CVE-2022-23055 | CVE | ExploitPatchThird Party Advisory |
| https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L134 | [email protected] | ExploitThird Party Advisory |
| https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L155 | [email protected] | ExploitThird Party Advisory |
| https://www.mend.io/vulnerability-database/CVE-2022-23055 | [email protected] | ExploitPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| frappe erpnext | >= 11.0.4, < 13.1.0 11.0.3 beta1 11.0.3 beta10 11.0.3 beta11 11.0.3 beta12 11.0.3 beta13 11.0.3 beta14 11.0.3 beta15 11.0.3 beta16 11.0.3 beta17 11.0.3 beta18 11.0.3 beta19 11.0.3 beta2 11.0.3 beta20 11.0.3 beta21 11.0.3 beta22 11.0.3 beta23 11.0.3 beta24 11.0.3 beta25 11.0.3 beta26 11.0.3 beta27 11.0.3 beta28 11.0.3 beta29 11.0.3 beta3 11.0.3 beta30 11.0.3 beta31 11.0.3 beta32 11.0.3 beta33 11.0.3 beta34 11.0.3 beta35 11.0.3 beta36 11.0.3 beta37 11.0.3 beta4 11.0.3 beta5 11.0.3 beta6 11.0.3 beta7 11.0.3 beta8 11.0.3 beta9 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 29, 2022 | Modified Analysis | [email protected] |
| Sep 30, 2022 | CVE Modified | [email protected] |
| Jul 5, 2022 | Initial Analysis | [email protected] |