An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-14966.json"