CVE-2025-66439 | Frappe ERPNext up to 15.89.0 get_outstanding_reference_documents from_posting_date sql injection
A vulnerability classified as critical was found in Frappe ERPNext up to 15.89.0. Affected by this vulnerability is the function get_outstanding_reference_documents. Executing a manipulation of the argument from_posting_date can lead to sql injection.
This vulnerability is registered as CVE-2025-66439. It is possible to launch the attack remotely. No exploit is available.