CVE-2025-68929
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
29/12/2025
Última modificación:
29/12/2025
Descripción
*** Pendiente de traducción *** Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.
Impacto
Puntuación base 3.x
9.00
Gravedad 3.x
CRÍTICA



