SQL Injection Vulnerability in Frappe HR Prior to Version 16.7.0
CVE-2026-54524
7.1HIGH
What is CVE-2026-54524?
Frappe HR, a popular open-source human resources management system, is susceptible to SQL injection attacks through filters in the Salary Payments report for users with the HR User role. This vulnerability arises in the report's backend code, where user-controlled input is improperly handled, enabling attackers to execute arbitrary SQL queries and extract sensitive database information. The issue has been addressed in version 16.7.0, making it crucial for users to upgrade to the latest version to safeguard their data.
Affected Version(s)
hrms < 16.7.0
