Description
ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attackers to infer database information. This issue has been fixed in versions 15.100.0 and 16.8.0.
INFO
Published Date :
2026-03-20T04:30:26.360Z
Last Modified :
2026-03-20T14:27:42.195Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-32954 vulnerability.
| Vendors | Products |
|---|---|
| Frappe |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-32954.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact