Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27055 | ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version could be retrieved. This issue is fixed in versions 14.89.2 and 15.76.0. |
Mon, 27 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:* |
Mon, 08 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 07 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe erpnext |
|
| Vendors & Products |
Frappe
Frappe erpnext |
Sat, 06 Sep 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version could be retrieved. This issue is fixed in versions 14.89.2 and 15.76.0. | |
| Title | ERP: Possibility of SQL injection due to missing validation | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-08T14:06:07.055Z
Reserved: 2025-09-01T20:03:06.532Z
Link: CVE-2025-58439
Updated: 2025-09-08T13:58:34.069Z
Status : Analyzed
Published: 2025-09-06T01:15:30.153
Modified: 2025-10-27T18:03:37.790
Link: CVE-2025-58439
No data.
OpenCVE Enrichment
Updated: 2025-09-07T15:24:57Z
EUVD