This issue affects Frappe CRM: 1.53.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 19 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:frappe:frappe_crm:1.53.1:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 03 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1. | |
| Title | Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller | |
| First Time appeared |
Frappe
Frappe frappe Crm |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:frappe:frappe_crm:1.53.1:*:linux:*:*:*:*:* cpe:2.3:a:frappe:frappe_crm:1.53.1:*:macos:*:*:*:*:* cpe:2.3:a:frappe:frappe_crm:1.53.1:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Frappe
Frappe frappe Crm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-12-03T16:16:06.493Z
Reserved: 2025-10-07T19:00:42.063Z
Link: CVE-2025-11461
Updated: 2025-12-03T16:15:51.609Z
Status : Analyzed
Published: 2025-11-26T18:15:46.847
Modified: 2025-12-19T16:32:47.197
Link: CVE-2025-11461
No data.
OpenCVE Enrichment
No data.