An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
Metrics
Affected Vendors & Products
References
History
Fri, 08 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe erpnext |
|
| CPEs | cpe:2.3:a:frappe:erpnext:10.1.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Erpnext
Erpnext erpnext |
Frappe
Frappe erpnext |
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-05T04:57:24.412Z
Reserved: 2018-01-02T00:00:00.000Z
Link: CVE-2018-3882
No data.
Status : Modified
Published: 2018-09-12T14:29:01.267
Modified: 2026-05-08T15:47:30.850
Link: CVE-2018-3882
No data.
OpenCVE Enrichment
No data.