CVE-2025-67289 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted…
Critical CVSS: 9.6

CVE-2025-67289

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
Vendor
Frappe
Product
Erpnext
CWE
CWE-79
Yayın Tarihi
2025-12-22 18:16:16
Güncelleme
2026-01-02 17:45:31
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar