- Description
- Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been patched in versions 14.94.3 and 15.58.0. There are no workarounds for this issue other than upgrading.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- security-advisories@github.com
- CWE-89
- Hype score
- Not currently trending
[CVE-2025-52895: HIGH] Critical SQL injection vulnerability in Frappe before versions 14.94.3 and 15.58.0 fixed. Upgrade now to avoid potential unauthorized access to sensitive data.#cve,CVE-2025-52895,#cybersecurity https://t.co/o51cBgkhdf https://t.co/uUUk4idyLe
@CveFindCom
30 Jun 2025
66 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-52895 Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could … https://t.co/0AgeQHZkuz
@CVEnew
30 Jun 2025
419 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1A94A0B-B5E4-4F08-8817-7BC2C61922AB",
"versionEndExcluding": "14.94.3"
},
{
"criteria": "cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD95653C-461E-44CD-A6D6-918E52A0A895",
"versionEndExcluding": "15.58.0",
"versionStartIncluding": "15.0.0"
}
],
"operator": "OR"
}
]
}
]