Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.
This issue affects Frappe CRM: 1.53.1.
References
| Link | Resource |
|---|---|
| https://fluidattacks.com/advisories/oz | Exploit Third Party Advisory |
| https://github.com/frappe/crm | Product |
| https://github.com/frappe/crm/pull/1339 | Issue Tracking Patch |
| https://fluidattacks.com/advisories/oz | Exploit Third Party Advisory |
| https://github.com/frappe/crm | Product |
Configurations
History
No history.
Information
Published : 2025-11-26 18:15
Updated : 2025-12-19 16:32
NVD link : CVE-2025-11461
Mitre link : CVE-2025-11461
CVE.ORG link : CVE-2025-11461
JSON object : View
Products Affected
frappe
- frappe_crm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
