CVE-2025-56381 | Frappe ERPNext 15.67.0 frappe.desk.reportview.get order_by/group_by sql injection (EUVD-2025-32133)
A vulnerability described as critical has been identified in Frappe ERPNext 15.67.0. This vulnerability affects unknown code of the file /api/method/frappe.desk.reportview.get. Executing manipulation of the argument order_by/group_by can lead to sql injection.
This vulnerability appears as CVE-2025-56381. The attack may be performed from remote. There is no available exploit.