THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-58375 (HIGH 8.1) — Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This

[NVD] CVE-2025-58375 (HIGH 8.1) — Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This

lownvdPublished 2025-09-06

CVE-2025-58375 CVSS: 8.1 HIGH Published: 2025-09-06T00:15:35.047

Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-58375