Frappe
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*
- < 14.93.2
- < 15.55.0
A SQL injection vulnerability has been identified in Frappe Framework versions prior to 14.93.2 and 15.55.0. This vulnerability could allow a malicious actor to access sensitive information. The issue arises from improper validation, which could be exploited through a specially crafted request.
Exploitation of this vulnerability allows for SQL injection, enabling access to sensitive information.
Users are advised to upgrade to Frappe Framework versions 14.93.2 or 15.55.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.