CVE-2025-52895

high

Description

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been patched in versions 14.94.3 and 15.58.0. There are no workarounds for this issue other than upgrading.

References

https://github.com/frappe/frappe/security/advisories/GHSA-mhj8-jfhf-mcw9

https://github.com/frappe/frappe/pull/31526

https://github.com/frappe/frappe/commit/f0933590103c80c6393647dd0403d399e64c951c

https://github.com/frappe/frappe/commit/c795e351be033070174437324d74f44759a744a6

Details

Source: Mitre, NVD

Published: 2025-06-30

Updated: 2025-07-08

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

CVSS v4

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00028