Frappe has possibility of SQL injection due to improper validations
Package
Affected versions
< 14.89.0
>= 15.0.0, < 15.51.0
Patched versions
14.89.0
15.51.0
Description
Published by the National Vulnerability Database
Mar 25, 2025
Published to the GitHub Advisory Database
Mar 25, 2025
Reviewed
Mar 25, 2025
Last updated
Mar 25, 2025
Impact
An SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information.
Workarounds
Upgrading is required, no other workaround is present.
Credits
Thanks to Thanh of Calif.io for reporting the issue
References