Vulnerabilities
Vulnerable Software
Frappe:  >> Frappe  >> 14.77.2  Security Vulnerabilities
Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could allow a malicious actor to access sensitive information. Versions 14.89.0 and 15.51.0 fix the issue. Upgrading is required; no other workaround is present.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-03-25
Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way that could lead to remote code execution. Versions 14.9.1 and 15.52.0 contain a patch for the vulnerability. There's no workaround; an upgrade is required.
CVSS Score
8.8
EPSS Score
0.007
Published
2025-03-25
Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. There's no workaround to fix this without upgrading.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-03-25


Contact Us

Shodan ® - All rights reserved