CVE-2025-28062

HIGH

ERPNEXT 14.82.1 and 14.74.3 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-28062. PoCs published by Ahmed Thaiban, Thvt0ne.

AI-analyzed exploit summary The exploit demonstrates a CSRF vulnerability in ERPNext versions <= 14.82.1 and 14.74.3, allowing account takeover via unauthorized state-changing operations such as user deletion, role assignment, and password reset. The PoC includes functional HTML snippets targeting specific API endpoints without CSRF protection.

Description

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.

Exploits (2)

exploitdb WORKING POC
by Ahmed Thaiban · textwebappspython
https://www.exploit-db.com/exploits/52283

The exploit demonstrates a CSRF vulnerability in ERPNext versions <= 14.82.1 and 14.74.3, allowing account takeover via unauthorized state-changing operations such as user deletion, role assignment, and password reset. The PoC includes functional HTML snippets targeting specific API endpoints without CSRF protection.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ERPNext <= 14.82.1, 14.74.3
No auth needed
Prerequisites: Victim must be logged into ERPNext as an administrator · Attacker must trick victim into clicking a malicious link
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 2 stars
by Thvt0ne · poc
https://github.com/Thvt0ne/CVE-2025-28062

This repository contains a working proof-of-concept for CVE-2025-28062, demonstrating CSRF vulnerabilities in ERPNext versions 14.82.1 and 14.74.3 that allow account takeover, user deletion, and privilege escalation.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ERPNext 14.82.1, 14.74.3
Auth required
Prerequisites: Authenticated admin session · Victim visits malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.0076
EPSS Percentile 50.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (2)
frappe/erpnext 14.74.3
frappe/erpnext 14.82.1
Published May 05, 2025
Tracked Since Feb 18, 2026