{"id":"CVE-2025-52047","details":"In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the filters.disabled parameter.","modified":"2026-07-15T01:49:07.672682693Z","published":"2025-09-30T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52047.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://github.com/Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures/blob/main/2025/Frappe%20Framework%20-%20Multiple%20SQL%20Injection.md"},{"type":"WEB","url":"https://github.com/frappe/erpnext/pull/49192/commits/6320f7290f93a5278ffdfaa790af70427c20a1c8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52047.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52047"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frappe/erpnext","events":[{"introduced":"2eb7a688cba73582e57f58905a8e68d401b92987"},{"last_affected":"2eb7a688cba73582e57f58905a8e68d401b92987"}],"database_specific":{"extracted_events":[{"introduced":"15.57.5"},{"last_affected":"15.57.5"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:frappe:erpnext:15.57.5:*:*:*:*:*:*:*"}}],"versions":["15.57.5","v15.57.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52047.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}