Frappe has possibility of SQL injection due to improper validations
Package
Affected versions
< 14.93.2
>= 15.0.0, < 15.55.0
Patched versions
14.93.2
15.55.0
Description
Published to the GitHub Advisory Database
Mar 26, 2025
Reviewed
Mar 26, 2025
Published by the National Vulnerability Database
Mar 26, 2025
Last updated
Mar 31, 2025
Impact
SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information.
Workarounds
Upgrading is required, no other workaround is present.
References