Frappe
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*
- < 15.86.0
- < 14.99.2
An error-based SQL injection vulnerability has been identified in the Frappe web application framework, affecting versions prior to 15.86.0 and 14.99.2. The vulnerability arises from insufficient validation of parameters in a specific endpoint, allowing attackers to manipulate SQL queries and potentially retrieve sensitive information, such as the application version.
Exploitation of this vulnerability allows for error-based SQL injection, where an attacker can interfere with the application's database queries. This could lead to unauthorized data access or manipulation.
The vulnerability can be reproduced by sending a crafted request to the affected endpoint that includes unvalidated parameters. This can be done by exploiting the SQL injection flaw to extract information from the database, such as the application version.
Users are advised to upgrade to Frappe versions 15.86.0 or 14.99.2, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.