Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32134 | Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter |
Fri, 03 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe erpnext
|
|
| CPEs | cpe:2.3:a:frappe:erpnext:15.67.0:*:*:*:*:*:*:* cpe:2.3:a:frappe:frappe:15.72.4:*:*:*:*:*:*:* |
|
| Vendors & Products |
Frappe erpnext
|
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe frappe |
|
| Vendors & Products |
Frappe
Frappe frappe |
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Thu, 02 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-02T18:06:15.422Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56380
Updated: 2025-10-02T18:06:05.247Z
Status : Analyzed
Published: 2025-10-02T14:15:45.767
Modified: 2025-10-03T16:18:50.157
Link: CVE-2025-56380
No data.
OpenCVE Enrichment
Updated: 2025-10-03T08:22:49Z
EUVD