CNNVD-202512-2665 Information
Dec 15, 2025
cve
CNNVD ID
CNNVD-202512-2665
Related CVE
- CNNVD Published: 2025-12-15
Description (Chinese)
ERPNext是印度ERPNext公司的一套开源的企业资源计划解决方案。 ERPNext 15.89.0及之前版本存在安全漏洞,该漏洞源于get_outstanding_reference_documents函数对to_posting_date参数处理不当,可能导致SQL注入攻击。
Description (English)
ERPNext is an open-source enterprise resource plan solution for ERPNext in India. The ERPNext 15.89.0 and previous versions have a security loophole, which stems from the inappropriate handling of to posting date parameters by the Get outstanding reference documents function, which may result in an SQL injection attack.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
ERPNext
Published
2025-12-15
Last Modified
2026-02-24
References
https://github.com/frappe/frappe/security https://iamanc.github.io/post/erpnext-sqli https://access.redhat.com/security/cve/cve-2025-66440
Patch
https://github.com/frappe/erpnext/releases
Share on: