PT-2024-20581 · Frappe · Frappe

Lamminhbao

·

Published

2024-03-20

·

Updated

2025-07-31

·

CVE-2024-24813

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 14.64.0 and 15.0.0
Description The issue is related to SQL injection from a particular whitelisted method, which can result in access to data that the user does not have permission to access. There are no known workarounds available for this issue.
Recommendations For versions prior to 14.64.0, update to version 14.64.0 or later. For versions prior to 15.0.0, update to version 15.0.0 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-24813
GHSA-FXFV-7GWX-54JH

Affected Products

Frappe