CNNVD-202512-2664 Information

CNNVD ID

CNNVD-202512-2664

CVE-2025-66439

  • CNNVD Published: 2025-12-15

Description (Chinese)

ERPNext是印度ERPNext公司的一套开源的企业资源计划解决方案。 ERPNext 15.89.0及之前版本存在安全漏洞,该漏洞源于get_outstanding_reference_documents函数对from_posting_date参数处理不当,可能导致SQL注入攻击。

Description (English)

ERPNext is an open-source enterprise resource plan solution for ERPNext in India. ERPNext 15.89.0 and previous versions have a security loophole, which stems from the inappropriate handling of from posting date parameters in the Get outstanding reference documents function, which may lead to an SQL injection attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

ERPNext

Published

2025-12-15

Last Modified

2026-02-24

References

https://github.com/frappe/frappe/security https://iamanc.github.io/post/erpnext-sqli https://access.redhat.com/security/cve/cve-2025-66439

Patch

https://github.com/frappe/erpnext/releases

Share on: