Description

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.

INFO

Published Date :

2025-12-29T15:06:31.756Z

Last Modified :

2025-12-29T16:12:29.988Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-68928 vulnerability.

Vendors Products
Frappe
  • Frappe
  • Frappe Crm

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact