Description
Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/report/salary_payments_based_on_payment_mode/salary_payments_based_on_payment_mode.py, get_conditions constructs filter clauses from user-controlled values and get_data incorporates those clauses into a string-formatted SQL query, allowing extraction of arbitrary database data. This issue is fixed in 16.7.0.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection via report filters
Action: Patch
AI Analysis

Impact

An authenticated user with the HR User role can craft SQL statements by manipulating filter values in the Salary Payments Based on Payment Mode report. The vulnerability lies in the dynamic construction of the WHERE clause and its direct insertion into a string-formatted SQL query, allowing the attacker to read arbitrary database data. The weakness is a classic SQL Injection flaw; the impact is limited to confidentiality leakage of database content, while integrity and availability are not directly affected by this exploit. The relevant CWE is 89.

Affected Systems

Frappe HRMS versions prior to 16.7.0 are affected. The patch is included in release v16.7.0 of the HRMS package. Any deployments using earlier releases with an HR User role should be updated to this latest version.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity of the vulnerability. The EPSS score of less than 1% means that real-world exploitation opportunities are presently low, and the issue is not listed in CISA’s KEV catalog. The likely attack vector requires an authenticated HR User to access the report. Should an attacker succeed, they could retrieve sensitive salary and employee data, potentially breaching confidentiality and violating privacy regulations.

Generated by OpenCVE AI on September 19, 2026 at 02:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Frappe HRMS v16.7.0 or later to apply the fix.
  • Audit and limit HR User role permissions, removing unnecessary database access to the Salary Payments report.
  • Enable monitoring of executed SQL queries and review application logs for abnormal patterns indicating injection attempts.

Generated by OpenCVE AI on September 19, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Frappe
Frappe hrms
Vendors & Products Frappe
Frappe hrms

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/report/salary_payments_based_on_payment_mode/salary_payments_based_on_payment_mode.py, get_conditions constructs filter clauses from user-controlled values and get_data incorporates those clauses into a string-formatted SQL query, allowing extraction of arbitrary database data. This issue is fixed in 16.7.0.
Title Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:00:53.087Z

Reserved: 2026-06-15T18:40:01.651Z

Link: CVE-2026-54524

cve-icon Vulnrichment

Updated: 2026-09-17T19:00:36.821Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:50.673

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')