CVE-2026-54524
Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/report/salary_payments_based_on_payment_mode/salary_payments_based_on_payment_mode.py, get_conditions constructs filter clauses from user-controlled values and get_data incorporates those clauses into a string-formatted SQL query, allowing extraction of arbitrary database data. This issue is fixed in 16.7.0.
| CWE | CWE-89 |
| Vendor | frappe |
| Product | hrms |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for frappe hrms
Be the first to know when new unknown vulnerabilities affecting frappe hrms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
frappe / hrms
< 16.7.0