CVE-2025-10655: Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data
Published Dec 9, 2025
·Updated
SQL Injection in Frappe HelpDesk in the dashboard getdashboarddata due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.
Affected Software
2 affected components
Frappe Frappe HelpDesk
Frappe HelpDesk=1.14.0
Event History
Dec 9, 2025
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-10655?
The severity of CVE-2025-10655 is rated as high due to potential SQL injection risks.
2
How do I fix CVE-2025-10655?
To fix CVE-2025-10655, update Frappe HelpDesk to the latest version where the SQL injection vulnerability is patched.
3
What systems are affected by CVE-2025-10655?
CVE-2025-10655 affects Frappe HelpDesk version 1.14.0 and potentially earlier versions.
4
What type of vulnerability is CVE-2025-10655?
CVE-2025-10655 is an SQL Injection vulnerability that results from unsafe concatenation of user inputs.
5
Can CVE-2025-10655 lead to data breaches?
Yes, CVE-2025-10655 can lead to unauthorized access to sensitive data, making it critical to address.