CNNVD-202512-031 Information

CNNVD ID

CNNVD-202512-031

CVE-2025-66205

  • CNNVD Published: 2025-12-01

Description (Chinese)

Frappe Technologies Frappe是印度Frappe Technologies公司的一个基于Python、Mariadb的并集成前端页面的Web开发框架。 Frappe Technologies Frappe 15.86.0之前版本和14.99.2之前版本存在SQL注入漏洞,该漏洞源于参数验证不足,可能导致SQL注入攻击。

Description (English)

Frappe Technologys Frappe is a Web development framework based on Python, Mariadb and integrated front-end pages of Frappe Technologys India. Frappe Technologies 15.86.0 and 14.99.2 pre-versions contain an injection loophole in SQL, which arises from inadequate verification of parameters, which may lead to SQL injection attacks.

Hazard Level

Medium

Vulnerability Type

SQL注入

Affected Vendor

Frappe Technologies

Published

2025-12-01

Last Modified

2026-02-24

References

https://github.com/frappe/frappe/commit/984c641bff9539b6126a01146096f133db6a955b https://github.com/frappe/frappe/security/advisories/GHSA-mp93-8vxr-hqq9

Patch

https://github.com/frappe/frappe/releases

Share on: