PT-2025-48549 · Frappé Technologies · Frappe

Published

2025-12-01

·

Updated

2025-12-26

·

CVE-2025-66205

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frappe versions prior to 15.86.0 Frappe versions prior to 14.99.2
Description Frappe, a full-stack web application framework, contains a flaw due to insufficient validation of parameters. This allows for error-based SQL injection through a specific endpoint, potentially enabling the retrieval of information such as the version.
Recommendations Update to Frappe version 15.86.0 or later. Update to Frappe version 14.99.2 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-66205

Affected Products

Frappe