In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at frappe/desk/doctype/tag/tag.py is vulnerable to SQL Injection, which allows an attacker to extract information from databases by injecting a SQL query into the dt parameter.
| Software | From | Fixed in |
|---|---|---|
| frappe / frappe | 14.0.0 | 14.96.10 |
| frappe / frappe | 15.0.0 | 15.72.0 |