Description

ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attackers to infer database information. This issue has been fixed in versions 15.100.0 and 16.8.0.

INFO

Published Date :

2026-03-20T04:30:26.360Z

Last Modified :

2026-03-20T14:27:42.195Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-32954 vulnerability.

Vendors Products
Frappe
  • Erpnext
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact