PT-2025-53727 · Frappe+1 · Crm+1

·

CVE-2025-68928

·

Published

2025-12-29

·

Updated

2025-12-29

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe CRM versions prior to 1.56.2
Description Authenticated users can set crafted URLs in a website field that are not sanitized, leading to cross-site scripting (XSS), a condition where malicious scripts are injected into trusted websites.
Recommendations Update to version 1.56.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-68928
GHSA-FM34-V6J7-CHWC

Affected Products

Crm
Frappe Crm