Vulnerabilities > CVE-2019-20529 - Files or Directories Accessible to External Parties vulnerability in Frappe 11.0.0/12.0.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |