Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-28062

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.1%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2025-28062
  • Frappe » Erpnext » Version: 14.74.3
    cpe:2.3:a:frappe:erpnext:14.74.3
  • Frappe » Erpnext » Version: 14.82.1
    cpe:2.3:a:frappe:erpnext:14.82.1


Contact Us

Shodan ® - All rights reserved