Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. There's no workaround to fix this without upgrading.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Aug 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:* | |
Metrics |
cvssV3_1
|
Tue, 25 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. There's no workaround to fix this without upgrading. | |
Title | Frappe vulnerable to information disclosure leading to account takeover | |
Weaknesses | CWE-200 CWE-287 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-03-25T15:05:42.656Z
Updated: 2025-03-25T15:52:36.718Z
Reserved: 2025-03-18T18:15:13.850Z
Link: CVE-2025-30214

No data.

Status : Analyzed
Published: 2025-03-25T15:15:26.460
Modified: 2025-08-01T15:28:15.670
Link: CVE-2025-30214

No data.