PT-2026-24784 · Frappe+1 · Frappe
Losevanni
+1
·
Published
2026-03-11
·
Updated
2026-03-13
·
CVE-2026-31877
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frappe versions prior to 15.84.0 and 14.99.0
Description
Frappe is a full-stack web application framework. A specially crafted request to a certain endpoint could result in SQL injection, potentially allowing an attacker to extract information they wouldn't otherwise be able to access. The issue involves a bypass of access controls due to improper field sanitization.
Recommendations
Update to Frappe version 15.84.0 or 14.99.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frappe