PT-2025-36422 · Frappe · Frappe
CVE-2025-58375
·
Published
2025-09-06
·
Updated
2026-08-17
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Frappe versions prior to 14.96.10
Frappe versions 15.0.0 through 15.71.0
Description
An insecure endpoint parameter is susceptible to error-based SQL Injection due to a lack of validation. This allows for the retrieval of sensitive information, such as versioning. SQL Injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations
Update to version 14.96.10.
Update to version 15.72.0.
Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frappe