CVE-2025-56381
02.10.2025, 14:15
ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.
| Vendor | Product | Version |
|---|---|---|
| frappe | erpnext | 15.67.0 |
| frappe | frappe | 15.72.4 |
𝑥
= Vulnerable software versions