frappe erpnext
cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*
- < 16.8.0
- < 15.100.0
A SQL injection vulnerability has been identified in Frappe ERPNext, specifically in versions prior to 16.8.0 and 15.100.0. This vulnerability arises from inadequate parameter validation in certain endpoints, allowing for time-based and boolean-based blind SQL injection. Attackers could exploit this flaw to infer information from the database.
Exploitation of this vulnerability allows for time-based and boolean-based blind SQL injection, enabling attackers to infer database information.
Users are advised to upgrade to ERPNext versions 16.8.0 or 15.100.0, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.