Frappe
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*
- < 15.84.0
- < 14.99.0
A SQL injection vulnerability has been identified in the Frappe web application framework, affecting versions prior to 15.84.0 and 14.99.0. The issue arises from improper sanitization of input fields, allowing attackers to craft specific requests that manipulate SQL queries. This exploitation could lead to unauthorized data extraction.
Exploitation of this vulnerability allows for SQL injection, enabling attackers to access information they should not be able to.
Users are advised to upgrade to Frappe versions 15.84.0 or 14.99.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.