CVE-2025-58375: Frappe has potential SQL Injection due to missing validation
Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
frappeto a version that resolves this vulnerability.Fixed in 14.96.10 - Upgrade
Upgrade
frappeto a version that resolves this vulnerability.Fixed in 15.72.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58375?
CVE-2025-58375 has a severity rating of high, with a score of 8.1.
What software is affected by CVE-2025-58375?
Frappe Framework versions 14.96.9 and below, and 15.0.0 through 15.71.0 are affected by CVE-2025-58375.
What type of vulnerability is CVE-2025-58375?
CVE-2025-58375 is a SQL Injection vulnerability due to missing validation.
How can I mitigate CVE-2025-58375?
To mitigate CVE-2025-58375, upgrade Frappe Framework to a version where the vulnerability is fixed.
What could an attacker achieve by exploiting CVE-2025-58375?
An attacker exploiting CVE-2025-58375 could retrieve sensitive information such as versioning through error-based SQL Injection.