CVE-2025-67289
EUVD-2025-20472722.12.2025, 18:16
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frappe | erpnext | 15.89.0 |
| frappe | frappe | 15.89.0 |
𝑥
= Vulnerable software versions