CVE-2025-52048

In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the `dt` parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*

History

20 Sep 2025, 02:57

Type Values Removed Values Added
References () https://github.com/Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures/blob/main/2025/Frappe%20Framework%20-%20Multiple%20SQL%20Injection.md - () https://github.com/Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures/blob/main/2025/Frappe%20Framework%20-%20Multiple%20SQL%20Injection.md - Exploit, Third Party Advisory
References () https://github.com/frappe/frappe/security/advisories/GHSA-mggw-6xqj-rphj - () https://github.com/frappe/frappe/security/advisories/GHSA-mggw-6xqj-rphj - Vendor Advisory
CPE cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*
First Time Frappe frappe
Frappe

15 Sep 2025, 20:15

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

15 Sep 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-15 16:15

Updated : 2025-09-20 02:57


NVD link : CVE-2025-52048

Mitre link : CVE-2025-52048

CVE.ORG link : CVE-2025-52048


JSON object : View

Products Affected

frappe

  • frappe
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')