PT-2025-51260 · Frappe · Erpnext
Published
2025-12-15
·
Updated
2026-01-05
·
CVE-2025-66439
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frappe ERPNext versions through 15.89.0
Description
An issue exists in Frappe ERPNext that allows an attacker to extract arbitrary data from the database. The
get outstanding reference documents() function, located at erpnext.accounts.doctype.payment entry.payment entry.py, is susceptible to SQL Injection. This is due to the direct interpolation of the from posting date parameter into a query without proper sanitization or parameter binding. The API endpoint is not explicitly mentioned. The vulnerable parameter is from posting date.Recommendations
Versions prior to 15.89.0 should be updated.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Erpnext