CVE-2025-66205

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of validation of parameters. Some information like version could be retrieved. This vulnerability is fixed in 15.86.0 and 14.99.2.
Configurations

No configuration.

History

01 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-01 21:15

Updated : 2025-12-02 17:16


NVD link : CVE-2025-66205

Mitre link : CVE-2025-66205

CVE.ORG link : CVE-2025-66205


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')