PT-2025-27460 · Frappe · Frappe

H41Th

·

Published

2025-06-30

·

Updated

2025-06-30

·

CVE-2025-52896

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Frappe versions prior to 14.94.2 Frappe versions prior to 15.57.0
Description: The issue allows authenticated users to upload malicious files via Data Import, leading to cross-site scripting (XSS).
Recommendations: For versions prior to 14.94.2, upgrade to version 14.94.2 to prevent cross-site scripting attacks. For versions prior to 15.57.0, upgrade to version 15.57.0 to prevent cross-site scripting attacks.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-52896
GHSA-HV29-66QG-2V6P

Affected Products

Frappe