PT-2025-27459 · Frappe · Frappe

Houssam Drissi

·

Publicado

2025-06-30

·

Atualizado

2025-06-30

·

CVE-2025-52895

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Frappe versions prior to 14.94.3 Frappe versions prior to 15.58.0
Description: The issue is related to a SQL injection vulnerability that could be achieved via a specially crafted request, potentially allowing malicious individuals to gain access to sensitive information.
Recommendations: For versions prior to 14.94.3, upgrade to version 14.94.3 or later. For versions prior to 15.58.0, upgrade to version 15.58.0 or later.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-52895
GHSA-MHJ8-JFHF-MCW9

Produtos afetados

Frappe