Beveiligingsadvies

CVE-2025-11461

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-11-26 17:45:05
Laatst bijgewerkt 2025-12-03 16:16:06
Toegewezen door Fluid Attacks
CVSS-score 7.1
Status PUBLISHED

Beschrijving

Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.