Error-Based SQL Injection Vulnerability in Frappe ERP Tool
CVE-2025-58439
8.1HIGH
What is CVE-2025-58439?
In Frappe ERP versions prior to 14.89.2 and from 15.0.0 to 15.75.1, the application did not adequately validate parameters for certain endpoints. This oversight allowed for error-based SQL Injection attacks, enabling unauthorized access to sensitive information such as application version details. Users are advised to update to versions 14.89.2 or 15.76.0 to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
erpnext >=15.0.0, < 15.76.0 < 15.0.0, 15.76.0
erpnext < 14.89.2 < 14.89.2
