PT-2025-40245 · Frappe · Erpnext

·

CVE-2025-52041

·

Published

2025-10-01

·

Updated

2025-10-06

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe ERPNext version 15.57.5
Description The get stock balance for() function located at erpnext/stock/doctype/stock reconciliation/stock reconciliation.py is susceptible to SQL Injection. An attacker can inject a SQL query through the inventory dimensions dict parameter, potentially allowing extraction of all information from databases.
Recommendations Apply a fix to the get stock balance for() function at erpnext/stock/doctype/stock reconciliation/stock reconciliation.py to prevent SQL Injection through the inventory dimensions dict parameter.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-52041

Affected Products

Erpnext