PT-2025-48161 · Frappe · Frappe Crm

Cristian Vargas

·

Publicado

2025-11-26

·

Atualizado

2026-01-13

·

CVE-2025-11461

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frappe CRM version 1.53.1
Description The Frappe CRM Dashboard Controller contains multiple SQL injection flaws. These flaws are due to the unsafe concatenation of user-controlled parameters into dynamic SQL statements. The issue allows for potential unauthorized database access and manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-11461

Produtos afetados

Frappe Crm