{"id":"CVE-2025-52050","details":"In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the expiry_date parameter.","modified":"2026-07-15T01:49:13.143116793Z","published":"2025-09-30T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52050.json"},"references":[{"type":"WEB","url":"https://github.com/Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures/blob/main/2025/Frappe%20Framework%20-%20Multiple%20SQL%20Injection.md"},{"type":"WEB","url":"https://github.com/frappe/erpnext/pull/49192/commits/8696ba2f5d9e99c799d4aef577f72f2fae5678e7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52050.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52050"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frappe/erpnext","events":[{"introduced":"2eb7a688cba73582e57f58905a8e68d401b92987"},{"last_affected":"2eb7a688cba73582e57f58905a8e68d401b92987"}],"database_specific":{"cpe":"cpe:2.3:a:frappe:erpnext:15.57.5:*:*:*:*:*:*:*","extracted_events":[{"introduced":"15.57.5"},{"last_affected":"15.57.5"}],"source":"CPE_STRING"}}],"versions":["15.57.5","v15.57.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52050.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}