Detects Frappe Framework instances before 15.84.0 / 14.99.0 where the DatabaseQuery.sanitize_fields() method only checks the first parenthesis in field names for blacklisted SQL functions. Wrapping a dangerous function like version() inside an allowed function like abs() bypasses the check entirely, enabling unauthenticated data extraction from the database.
Is your app exploitable through CVE-2026-31877?
Scan your domain free