CNNVD-202512-031 Information
CNNVD ID
CNNVD-202512-031
Related CVE
- CNNVD Published: 2025-12-01
Description (Chinese)
Frappe Technologies Frappe是印度Frappe Technologies公司的一个基于Python、Mariadb的并集成前端页面的Web开发框架。 Frappe Technologies Frappe 15.86.0之前版本和14.99.2之前版本存在SQL注入漏洞,该漏洞源于参数验证不足,可能导致SQL注入攻击。
Description (English)
Frappe Technologys Frappe is a Web development framework based on Python, Mariadb and integrated front-end pages of Frappe Technologys India. Frappe Technologies 15.86.0 and 14.99.2 pre-versions contain an injection loophole in SQL, which arises from inadequate verification of parameters, which may lead to SQL injection attacks.
Hazard Level
Medium
Vulnerability Type
SQL注入
Affected Vendor
Frappe Technologies
Published
2025-12-01
Last Modified
2026-02-24
References
https://github.com/frappe/frappe/commit/984c641bff9539b6126a01146096f133db6a955b https://github.com/frappe/frappe/security/advisories/GHSA-mp93-8vxr-hqq9
Patch
https://github.com/frappe/frappe/releases
Share on: