A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
References
Link | Resource |
---|---|
https://github.com/Thvt0ne/CVE-2025-28062 | Exploit |
https://github.com/frappe/erpnext | Product |
Configurations
Configuration 1 (hide)
|
History
17 Jun 2025, 14:13
Type | Values Removed | Values Added |
---|---|---|
First Time |
Frappe erpnext
Frappe |
|
CPE | cpe:2.3:a:frappe:erpnext:14.82.1:*:*:*:*:*:*:* cpe:2.3:a:frappe:erpnext:14.74.3:*:*:*:*:*:*:* |
|
References | () https://github.com/Thvt0ne/CVE-2025-28062 - Exploit | |
References | () https://github.com/frappe/erpnext - Product |
13 May 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-352 | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
05 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-05 16:15
Updated : 2025-06-17 14:13
NVD link : CVE-2025-28062
Mitre link : CVE-2025-28062
CVE.ORG link : CVE-2025-28062
JSON object : View
Products Affected
frappe
- erpnext
CWE
CWE-352
Cross-Site Request Forgery (CSRF)