 
        
            ERPNext 14.82.1 – Account Takeover via Cross-Site Request Forgery (CSRF)
# Exploit Title: ERPNext 14.82.1 – Account Takeover via Cross-Site Request Forgery (CSRF) # Google Dork: inurl:”/api/method/frappe” # Date: 2025-04-29 # Exploit Author: Ahmed Thaiban (Thvt0ne) # Vendor Homepage: https://erpnext.com # Software Link: https://github.com/frappe/erpnext # Version: <= 14.82.1, 14.74.3 (Tested) # Tested on: Linux (Ubuntu 20.04), Chrome, Firefox. # CVE : CVE-2025-28062 # Category: WebApps …



 
                         
                         
                         
                         
                         
                         
         
         
         
         
        ![[Guest Diary] Anatomy of a Linux SSH Honeypot Attack: Detailed Analysis of Captured Malware](https://informernow.online/wp-content/uploads/2025/06/2025-06-08_figure1-400x250.png) 
         
        