Frappe Framework 13.4.0 Remote Code Execution
# Exploit Title: Frappe Framework (ERPNext) 13.4.0 - Remote Code Execution (Authenticated)# Exploit Author: Sander Ferdinand# Date: 2023-06-07# Version: 13.4.0# Vendor Homepage: http://erpnext.org# Software Link: https://github.com/frappe/frappe/# Tested on: Ubuntu 22.04# CVE : noneSilly sandbox escape.> Frappe Framework uses the RestrictedPython library to restrict access to methods available for server scripts.Requirements:- 'System Manager' role (which is