Cross-Site Scripting Vulnerability in Frappe CRM Affects User Input Handling
CVE-2025-68928
5.4MEDIUM
What is CVE-2025-68928?
Frappe CRM, an open-source customer relationship management tool, is vulnerable due to improper handling of URLs in a website field by authenticated users. This lack of sanitization can lead to cross-site scripting (XSS) attacks, allowing malicious scripts to be executed in the context of a user's browser. The vulnerability has been addressed in version 1.56.2, which implements appropriate input sanitization measures. Users are urged to upgrade to the latest version as no workarounds are available.
Affected Version(s)
crm < 1.56.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
