{"id":"CVE-2025-58375","summary":"Frappe has potential SQL Injection due to missing validation","details":"Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.","aliases":["CVE-2025-52048","GHSA-mggw-6xqj-rphj"],"modified":"2026-08-18T03:30:56.154349455Z","published":"2025-09-06T00:15:35.047Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58375.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-89"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58375.json"},{"type":"ADVISORY","url":"https://github.com/frappe/frappe/security/advisories/GHSA-mggw-6xqj-rphj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58375"},{"type":"FIX","url":"https://github.com/frappe/frappe/commit/2dab009c8b15e29aa14bcd421eee8c6b2dc0fce6"},{"type":"FIX","url":"https://github.com/frappe/frappe/commit/ec70383ef0196d7b64fcf51b230483dac095a68b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frappe/frappe","events":[{"introduced":"b8c1f492c492f7cbbfd3cc768234fbb244fd3737"},{"fixed":"82f0cc1d09115e84d6acb37fb2b010b2aba69bfc"},{"fixed":"2dab009c8b15e29aa14bcd421eee8c6b2dc0fce6"},{"fixed":"ec70383ef0196d7b64fcf51b230483dac095a68b"}],"database_specific":{"extracted_events":[{"introduced":"15.0.0"},{"fixed":"15.71.0"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v15.70.0","v15.69.3","v15.69.2","v15.69.1","v15.69.0","v15.68.1","v15.68.0","v15.67.0","v15.66.1","v15.66.0","v15.65.2","v15.65.1","v15.65.0","v15.64.0","v15.63.1","v15.63.0","v15.62.0","v15.61.0","v15.60.0","v15.59.0","v15.58.1","v15.58.0","v15.57.2","v15.57.1","v15.57.0","v15.56.1","v15.56.0","v15.55.2","v15.55.1","v15.55.0","v15.54.1","v15.54.0","v15.53.0","v15.52.0","v15.51.2","v15.51.1","v15.51.0","v15.50.1","v15.50.0","v15.49.1","v15.49.0","v15.48.1","v15.48.0","v15.47.2","v15.47.1","v15.47.0","v15.46.0","v15.45.1","v15.45.0","v15.44.2","v15.44.1","v15.44.0","v15.43.0","v15.42.0","v15.41.0","v15.40.6","v15.40.5","v15.40.4","v15.40.3","v15.40.2","v15.40.1","v15.40.0","v15.39.2","v15.39.1","v15.39.0","v15.38.0","v15.37.0","v15.36.1","v15.36.0","v15.35.0","v15.34.1","v15.34.0","v15.33.3","v15.33.2","v15.33.1","v15.33.0","v15.32.0","v15.31.0","v15.30.0","v15.29.2","v15.29.1","v15.29.0","v15.28.0","v15.27.0","v15.26.0","v15.25.0","v15.24.1","v15.24.0","v15.23.0","v15.22.0","v15.21.0","v15.20.0","v15.19.1","v15.19.0","v15.18.2","v15.18.1","v15.18.0","v15.17.3","v15.17.2","v15.17.1","v15.17.0","v15.16.1","v15.16.0","v15.15.0","v15.14.1","v15.14.0","v15.13.0","v15.12.0","v15.11.0","v15.10.0","v15.9.0","v15.8.1","v15.8.0","v15.7.0","v15.6.1","v15.6.0","v15.5.0","v15.4.1","v15.4.0","v15.3.0","v15.2.1","v15.2.0","v15.1.0","v15.0.2","v15.0.1","v15.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58375.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}