PT-2025-36422 · Frappe · Frappe

CVE-2025-58375

·

Published

2025-09-06

·

Updated

2026-08-17

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 14.96.10 Frappe versions 15.0.0 through 15.71.0
Description An insecure endpoint parameter is susceptible to error-based SQL Injection due to a lack of validation. This allows for the retrieval of sensitive information, such as versioning. SQL Injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations Update to version 14.96.10. Update to version 15.72.0.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58375
GHSA-MGGW-6XQJ-RPHJ

Affected Products

Frappe