CVE-2025-62407
Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, if a specific type of URL was passed in. This vulnerability is fixed in 14.98.0 and 15.83.0.
Vendor
Product
CWE
Yayın Tarihi
2025-10-16 18:15:39
Güncelleme
2025-10-23 20:16:18
Source Identifier
security-advisories@github.com
KEV Date Added
-