THREAT OPS › Threat News › [NVD] CVE-2025-58375 (HIGH 8.1) — Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This
[NVD] CVE-2025-58375 (HIGH 8.1) — Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This
CVE-2025-58375 CVSS: 8.1 HIGH Published: 2025-09-06T00:15:35.047
Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.
Indicators of compromise
- CVE-2025-58375cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-58375