CVE-2025-52048

In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the `dt` parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-15 16:15

Updated : 2025-09-20 02:57


NVD link : CVE-2025-52048

Mitre link : CVE-2025-52048

CVE.ORG link : CVE-2025-52048


JSON object : View

Products Affected

frappe

  • frappe
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')