NONE · 0

CVE-2026-54524

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Paym...

Vulnerability Description

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/report/salary_payments_based_on_payment_mode/salary_payments_based_on_payment_mode.py, get_conditions constructs filter clauses from user-controlled values and get_data incorporates those clauses into a string-formatted SQL query, allowing extraction of arbitrary database data. This issue is fixed in 16.7.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-54524?

CVE-2026-54524 is a documented vulnerability. Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Paym...

How severe is CVE-2026-54524?

CVSS scoring is not yet available for CVE-2026-54524. Check NVD for updates.

Is there a patch for CVE-2026-54524?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.