CVE-2025-56380 | Frappe Framework 15.72.4 API Endpoint frappe.client.get_value fieldname sql injection (EUVD-2025-32134)
A vulnerability classified as critical has been found in Frappe Framework 15.72.4. Affected by this issue is the function frappe.client.get_value of the component API Endpoint. Performing manipulation of the argument fieldname results in sql injection.
This vulnerability is known as CVE-2025-56380. Remote exploitation of the attack is possible. No exploit is available.