PT-2025-48549 · Frappé Technologies · Frappe

Published

2025-12-01

·

Updated

2025-12-26

·

CVE-2025-66205

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 15.86.0 Frappe versions prior to 14.99.2
Description Frappe, a full-stack web application framework, contains a flaw due to insufficient validation of parameters. This allows for error-based SQL injection through a specific endpoint, potentially enabling the retrieval of information such as the version.
Recommendations Update to Frappe version 15.86.0 or later. Update to Frappe version 14.99.2 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-66205
GHSA-MP93-8VXR-HQQ9

Affected Products

Frappe