CVE-2025-30217: Frappe has possibility of SQL injection due to improper validations
Impact SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information.
Workarounds Upgrading is required, no other workaround is present.
Other sources
Frappe is a full-stack web application framework. Prior to versions 14.93.2 and 15.55.0, a SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information. Versions 14.93.2 and 15.55.0 contain a patch for the issue. No known workarounds are available.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/frappeto a version that resolves this vulnerability.Fixed in 15.55.0 - Upgrade
Upgrade
pip/frappeto a version that resolves this vulnerability.Fixed in 14.93.2 - Upgrade
Upgrade
Frappe Frameworkto a version that resolves this vulnerability.Fixed in 14.93.2 - Upgrade
Upgrade
Frappe Frameworkto a version that resolves this vulnerability.Fixed in 15.55.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30217?
CVE-2025-30217 has a high severity level due to its potential for SQL injection, which can lead to unauthorized access to sensitive information.
How do I fix CVE-2025-30217?
To fix CVE-2025-30217, upgrade to version 15.55.0 or higher of the Frappe framework.
What kind of vulnerability is CVE-2025-30217?
CVE-2025-30217 is an SQL injection vulnerability that can be exploited through specially crafted requests.
Which versions of Frappe are affected by CVE-2025-30217?
CVE-2025-30217 affects Frappe versions between 15.0.0 and 15.55.0, as well as versions up to 14.93.2.
What can attackers do using CVE-2025-30217?
Attackers exploiting CVE-2025-30217 can gain unauthorized access to sensitive information stored in the database.