Skip to content

Information disclosure leading to account takeover

High
akhilnarang published GHSA-qrv3-jc3h-f3m6 Mar 25, 2025

Package

pip frappe (pip)

Affected versions

<14.89.0
<15.51.0

Patched versions

14.89.0
15.51.0

Description

Impact

Making crafted requests could lead to information disclosure that could further lead to account takeover.

Workarounds

There's no workaround to fix this without upgrading.

Credits

Thanks to Thanh of Calif.io for reporting the issue

Severity

High

CVE ID

CVE-2025-30214

Weaknesses

No CWEs

Credits