CVE-2025-66205: Frappe has the possibility of SQL Injection due to improper validations
Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of validation of parameters. Some information like version could be retrieved. This vulnerability is fixed in 15.86.0 and 14.99.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66205?
CVE-2025-66205 is classified as a high-severity vulnerability due to its potential for error-based SQL injection.
How do I fix CVE-2025-66205?
To fix CVE-2025-66205, upgrade Frappe Framework to version 15.86.0 or later, or 14.99.2 or later.
What causes CVE-2025-66205?
CVE-2025-66205 is caused by a lack of validation of parameters in certain endpoints, leading to error-based SQL injection.
What versions of Frappe Framework are affected by CVE-2025-66205?
CVE-2025-66205 affects Frappe Framework versions prior to 15.86.0 and 14.99.2.
What information can be retrieved through CVE-2025-66205?
CVE-2025-66205 allows attackers to retrieve certain information, such as version details of the Frappe Framework.