SQL injection in ERPNext - CVE-2025-52040
Published: April 24, 2026
ERPNext
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in certain endpoints when handling request parameters. A remote user can send specially crafted parameters to disclose sensitive information.
The issue is error-based and may allow retrieval of information such as version details.