CVE-2026-41320 | Frappe hrms up to 14.38.0/15.53.x Request sql injection (GHSA-745c-5q8r-vgj2)
A vulnerability categorized as critical has been discovered in Frappe hrms up to 14.38.0/15.53.x. This impacts an unknown function of the component Request Handler. Executing a manipulation can lead to sql injection.
This vulnerability is handled as CVE-2026-41320. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.