CVE-2025-11461

Publication date

2025-11-26 17:45:05

Family

Fluid Attacks

State

PUBLISHED

Description

Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.