datnlq
11 exploits
Active since Jul 2025
Frappe ERPNext 15.57.5 - SQL Injection via txt Parameter in get_material_requests_based_on_supplier()
CVSS 8.2
Frappe ERPNext 15.57.5 - SQL Injection via blanket_order_type Parameter
CVSS 8.2
Frappe ERPNext 15.57.5 - SQL Injection via inventory_dimensions_dict Parameter
CVSS 8.2
Frappe ERPNext 15.57.5 - SQL Injection via txt Parameter in get_rfq_containing_supplier()
CVSS 8.2
Frappe ERPNext v15.57.5 - SQL Injection via import_coa() company parameter
CVSS 6.5
Frappe ERPNext 15.57.5 - SQL Injection via get_stock_balance() inventory_dimensions_dict Parameter
CVSS 7.5
Frappe ErpNext v15.57.5 - SQL Injection via filters.disabled Parameter
CVSS 6.5
Frappe 14.0.0-14.96.10 - SQL Injection via dt Parameter in add_tag()
CVSS 6.5
Frappe ErpNext v15.57.5 - SQL Injection via timelog Parameter in get_timesheet_detail_rate()
CVSS 6.5
Frappe ERPNext 15.57.5 - SQL Injection via Loyalty Program Expiry Date Parameter
CVSS 6.5
Totolink X6000R V9.4.0cu.1360_B20241207 - Unauthenticated Command Injection via tz Parameter
CVSS 6.5