Frappe-ErpNext-AuthBypass-SSTItoRCE. A critical vulnerability in ERPNext’s Jinja templating implementation allows SSTI attacks that result in remote code execution. Combined with an account hijacking flaw, this enables unauthenticated attackers to fully compromise the system.

github.com/mchklt/Frappe-ErpNext-AuthBypass-SSTItoRCE

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.