Vulnerabilities
Vulnerable Software
Frappe:  >> Erpnext  >> 14.82.1  Security Vulnerabilities
ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version could be retrieved. This issue is fixed in versions 14.89.2 and 15.76.0.
CVSS Score
8.1
EPSS Score
0.003
Published
2025-09-06
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
CVSS Score
8.1
EPSS Score
0.008
Published
2025-05-05


Contact Us

Shodan ® - All rights reserved