CVE-2025-28062

Source
https://cve.org/CVERecord?id=CVE-2025-28062
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-28062.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-28062
Published
2025-05-05T00:00:00Z
Modified
2026-07-15T01:49:22.002671359Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/28xxx/CVE-2025-28062.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/frappe/erpnext

Affected ranges

Type
GIT
Repo
https://github.com/frappe/erpnext
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:frappe:erpnext:14.74.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:frappe:erpnext:14.82.1:*:*:*:*:*:*:*"
    ],
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "14.74.3"
        },
        {
            "last_affected": "14.74.3"
        },
        {
            "introduced": "14.82.1"
        },
        {
            "last_affected": "14.82.1"
        }
    ]
}

Affected versions

14.*
14.74.3
14.82.1
v14.*
v14.74.3
v14.74.4
v14.74.5
v14.74.6
v14.74.7
v14.74.8
v14.75.0
v14.75.1
v14.75.2
v14.76.0
v14.77.0
v14.77.1
v14.77.2
v14.77.3
v14.78.0
v14.78.1
v14.78.2
v14.78.3
v14.78.4
v14.78.5
v14.78.6
v14.78.7
v14.78.8
v14.78.9
v14.79.0
v14.80.0
v14.81.0
v14.82.0
v14.82.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-28062.json"