PT-2025-53727 · Frappe+1 · Crm+1

Stolichnayer

·

Published

2025-12-29

·

Updated

2025-12-29

·

CVE-2025-68928

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe CRM versions prior to 1.56.2
Description Authenticated users can set crafted URLs in a website field that are not sanitized, leading to cross-site scripting (XSS), a condition where malicious scripts are injected into trusted websites.
Recommendations Update to version 1.56.2.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-68928
GHSA-FM34-V6J7-CHWC

Affected Products

Crm
Frappe Crm