CVE-2025-52040 | Frappe ERPNext 15.57.5 queries.py get_blanket_orders blanket_order_type sql injection
A vulnerability described as critical has been identified in Frappe ERPNext 15.57.5. Affected by this issue is the function get_blanket_orders of the file erpnext/controllers/queries.py. The manipulation of the argument blanket_order_type results in sql injection.
This vulnerability is identified as CVE-2025-52040. The attack can be executed remotely. There is not any exploit available.
It is best practice to apply a patch to resolve this issue.