CVE-2025-66437 | Frappe ERPNext up to 15.89.0 get_address_display address_dict special elements used in a template engine
A vulnerability has been found in Frappe ERPNext up to 15.89.0 and classified as critical. This vulnerability affects the function get_address_display. This manipulation of the argument address_dict causes improper neutralization of special elements used in a template engine.
This vulnerability appears as CVE-2025-66437. The attack may be initiated remotely. There is no available exploit.