Frappe CRM Cross-Site Scripting Vulnerability in Website Field
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Frappe CRM versions prior to 1.56.2. The issue allows authenticated users to inject crafted URLs into a website field, which are not properly sanitized, leading to XSS. The vulnerability has been patched in version 1.56.2.
Impact
Exploitation of this vulnerability allows for authenticated cross-site scripting, where injected scripts can be executed in the context of the user.
Remediation
Users are advised to upgrade to Frappe CRM version 1.56.2 or later.
Added: Dec 29, 2025, 3:23 PM
Updated: Dec 29, 2025, 4:00 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.7exploitability
5.7remediation
7.7relevance
1.6threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
