CNNVD-202509-4473 Information

CNNVD ID

CNNVD-202509-4473

CVE-2025-52050

  • CNNVD Published: 2025-09-30

Description (Chinese)

Frappe Technologies Frappe是印度Frappe Technologies公司的一个基于Python、Mariadb的并集成前端页面的Web开发框架。 Frappe Technologies Frappe 15.57.5版本存在安全漏洞,该漏洞源于对expiry_date参数未进行充分验证,可能导致SQL注入攻击。

Description (English)

Frappe Technologys Frappe is a Web development framework based on Python, Mariadb and integrated front-end pages of Frappe Technologys India. There is a security loophole in version 1557.5 of Frappe Technology Technologies, which stems from the failure to adequately validate expery date parameters, which could lead to an attack by SQL.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Frappe Technologies

Published

2025-09-30

Last Modified

2026-02-24

References

https://github.com/Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures/blob/main/2025/Frappe%20Framework%20-%20Multiple%20SQL%20Injection.md https://github.com/frappe/erpnext/pull/49192/commits/8696ba2f5d9e99c799d4aef577f72f2fae5678e7

Patch

https://github.com/frappe/erpnext/releases

Share on: