PT-2025-42517 · Frappe · Frappe

Published

2025-10-16

·

Updated

2025-10-17

·

CVE-2025-62407

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 14.98.0 Frappe versions prior to 15.83.0
Description An open redirect issue existed in Frappe due to improper handling of the redirect argument on the login page when a specific type of URL was provided. This could allow an attacker to redirect users to a malicious website.
Recommendations Update to Frappe version 14.98.0 or later. Update to Frappe version 15.83.0 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62407
GHSA-J9JR-QRPJ-G855

Affected Products

Frappe