PT-2025-48161 · Frappe · Frappe Crm

Cristian Vargas

·

Published

2025-11-26

·

Updated

2026-01-13

·

CVE-2025-11461

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frappe CRM version 1.53.1
Description The Frappe CRM Dashboard Controller contains multiple SQL injection flaws. These flaws are due to the unsafe concatenation of user-controlled parameters into dynamic SQL statements. The issue allows for potential unauthorized database access and manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-11461

Affected Products

Frappe Crm