Frappe Information Disclosure Vulnerability Leading to Account Takeover

Vulnerability

A vulnerability in the Frappe web application framework prior to versions 14.89.0 and 15.51.0 allows crafted requests to cause information disclosure, potentially leading to account takeover. The issue has been fixed in versions 14.89.0 and 15.51.0. There is no workaround available other than upgrading.

Impact

Exploitation of this vulnerability could result in unauthorized account access.

Remediation

Users should upgrade to Frappe versions 14.89.0 or 15.51.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.0
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.