9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the from_posting_date parameter, which is directly interpolated into the query without proper sanitization or parameter binding.
AI Analysis
SQL Injection vulnerability in ERPNext through 15.89.0, allowing an attacker to extract arbitrary data from the database
Basic Information
ID
CVE-2025-66439
Source
mitre
Published
Dec 15, 2025 at 00:00
Modified
Dec 16, 2025 at 15:07
Affected Product
Vendor
Frappe
Product
ERPNext
Version
15.89.0
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Frappe
Product
ERPNext
Version
15.89.0