CVE-2025-52050
- EPSS 0.03%
- Veröffentlicht 30.09.2025 14:15:39
- Zuletzt bearbeitet 03.10.2025 16:19:39
In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by inj...
CVE-2025-52049
- EPSS 0.03%
- Veröffentlicht 30.09.2025 14:15:39
- Zuletzt bearbeitet 03.10.2025 16:19:48
In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into the...
CVE-2025-52043
- EPSS 0.03%
- Veröffentlicht 30.09.2025 14:15:39
- Zuletzt bearbeitet 03.10.2025 16:20:49
In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnerable to SQL injection, which allows an attacker to extract all information from databases by injecting...
CVE-2025-52044
- EPSS 0.03%
- Veröffentlicht 16.09.2025 00:00:00
- Zuletzt bearbeitet 20.09.2025 02:58:35
In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into inventory_dimensions_dict parameter.
CVE-2025-58439
- EPSS 0.04%
- Veröffentlicht 06.09.2025 00:30:26
- Zuletzt bearbeitet 27.10.2025 18:03:37
ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version coul...
CVE-2025-28062
- EPSS 0.22%
- Veröffentlicht 05.05.2025 00:00:00
- Zuletzt bearbeitet 17.06.2025 14:13:04
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF...
CVE-2022-28598
- EPSS 15.2%
- Veröffentlicht 22.08.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:33
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2022-23055
- EPSS 0.3%
- Veröffentlicht 22.06.2022 09:15:08
- Zuletzt bearbeitet 21.11.2024 06:47:53
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the...
CVE-2022-23058
- EPSS 0.24%
- Veröffentlicht 22.06.2022 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:47:54
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.
CVE-2022-23057
- EPSS 0.21%
- Veröffentlicht 22.06.2022 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:47:54
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.