Vulnerability Description
ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version could be retrieved. This issue is fixed in versions 14.89.2 and 15.76.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frappe | Erpnext | < 14.89.2 |
Related Weaknesses (CWE)
References
- https://github.com/frappe/erpnext/pull/49219Issue Tracking
- https://github.com/frappe/erpnext/pull/49220Issue Tracking
- https://github.com/frappe/erpnext/security/advisories/GHSA-fvjw-5w9q-6v39Vendor Advisory
FAQ
What is CVE-2025-58439?
CVE-2025-58439 is a vulnerability with a CVSS score of 8.1 (HIGH). ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based...
How severe is CVE-2025-58439?
CVE-2025-58439 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-58439?
Check the references section above for vendor advisories and patch information. Affected products include: Frappe Erpnext.