CVE-2025-56381: SQL Injection
Published Oct 2, 2025
·Updated
ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the orderby and groupby parameters.
Affected Software
3 affected components
ERPNext ERPNext
Frappe ERPNext=15.67.0
Frappe frappe=15.72.4
Event History
Oct 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56381?
CVE-2025-56381 is considered a critical vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2025-56381?
To mitigate CVE-2025-56381, upgrade to the latest version of ERPNEXT where the vulnerabilities have been patched.
3
What are the potential impacts of CVE-2025-56381?
CVE-2025-56381 can lead to unauthorized access to database information and compromise the integrity of the application.
4
Which versions of ERPNEXT are affected by CVE-2025-56381?
CVE-2025-56381 affects ERPNEXT version 15.67.0.
5
How can I identify if my system is vulnerable to CVE-2025-56381?
You can identify CVE-2025-56381 vulnerability by testing the /api/method/frappe.desk.reportview.get endpoint with malicious SQL injection payloads.