PT-2025-39989 · Frappe · Erpnext

·

CVE-2025-52043

·

Published

2025-09-30

·

Updated

2025-09-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe ERPNext version 15.57.5
Description The import coa() function located at erpnext/accounts/doctype/chart of accounts importer/chart of accounts importer.py is susceptible to SQL injection. An attacker can inject a SQL query through the company parameter, potentially allowing extraction of all data from databases. The vulnerable function is import coa().
Recommendations Apply a fix for Frappe ERPNext version 15.57.5 to address the SQL injection issue in the import coa() function.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-52043

Affected Products

Erpnext