天下漏洞,尽知其名
MEDIUM

CVE-2026-101006 Frappe HR 权限验证不当漏洞

影响远程攻击者可越权查看他人考勤、报销等敏感数据

AI 研判

Frappe HR 16.15.0 及之前版本的 hrms/api/__init__.py 中,get_expense_claims、get_shift_requests、get_attendance_requests 三个接口在权限校验时未正确验证 employee 参数,导致授权判断错误。攻击者可远程利用该缺陷绕过权限限制,访问不属于自己的员工数据。厂商已确认该问题并完成修复。

影响范围

Frappe HR

Frappe HR 16.15.0 及更早版本;具体受影响版本范围以厂商公告为准,暂无更详细的公开版本信息。

漏洞详情

漏洞属于授权校验不当(越权访问)。接口在处理请求时直接信任客户端传入的 employee 参数,未校验当前登录用户是否有权访问该员工的数据,从而造成水平越权。攻击者只需构造带有他人 employee 标识的请求,即可读取对应的报销申请、排班申请和考勤申请记录。

利用条件与风险

利用前提是攻击者拥有可访问相关接口的账号并能远程调用,无需高权限;CVSS 4.3 属中危,主要风险为敏感人事与考勤数据泄露,实战中利用门槛较低。

修复建议

厂商表示该问题已被报告并完成修复,建议升级至包含修复的 Frappe HR 版本;临时缓解措施暂无公开信息,可考虑限制相关接口访问权限或对 employee 参数增加服务端归属校验。

原始情报

A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: “This issue has already been reported by another individual, and based on that, we have fixed it.”