Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.
History

Wed, 03 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Nov 2025 18:00:00 +0000

Type Values Removed Values Added
Description Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.
Title Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller
First Time appeared Frappe
Frappe frappe Crm
Weaknesses CWE-89
CPEs cpe:2.3:a:frappe:frappe_crm:1.53.1:*:linux:*:*:*:*:*
cpe:2.3:a:frappe:frappe_crm:1.53.1:*:macos:*:*:*:*:*
cpe:2.3:a:frappe:frappe_crm:1.53.1:*:windows:*:*:*:*:*
Vendors & Products Frappe
Frappe frappe Crm
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2025-11-26T17:45:05.113Z

Updated: 2025-12-03T16:16:06.493Z

Reserved: 2025-10-07T19:00:42.063Z

Link: CVE-2025-11461

cve-icon Vulnrichment

Updated: 2025-12-03T16:15:51.609Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-26T18:15:46.847

Modified: 2025-12-03T17:15:49.260

Link: CVE-2025-11461

cve-icon Redhat

No data.