6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the `dt` parameter.
AI Analysis
SQL Injection vulnerability in Frappe Framework's add_tag() function allows attackers to extract database information via the `dt` parameter.
Basic Information
ID
CVE-2025-52048
Source
mitre
Published
Sep 15, 2025 at 00:00
Modified
Sep 15, 2025 at 19:13
Affected Product
Vendor
n/a
Product
n/a
Version
n/a
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
6.5 / 10
AI Severity
MEDIUM
Vendor
Frappe Technologies
Product
Frappe Framework
Version
15.x.x before 15.72.0, 14.x.x before 14.96.10