8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Description
ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version could be retrieved. This issue is fixed in versions 14.89.2 and 15.76.0.
Basic Information
ID
CVE-2025-58439
Source
GitHub_M
Published
Sep 6, 2025 at 00:30
Affected Product
Vendor
frappe
Product
erpnext
Version
>=15.0.0, < 15.76.0
Affected Versions
frappe erpnext >=15.0.0, < 15.76.0
frappe erpnext < 14.89.2
frappe erpnext < 14.89.2