Vulnerabilities
Vulnerable Software
Frappe:  >> Learning  >> 2.34.1  Security Vulnerabilities
Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL.
CVSS Score
5.3
EPSS Score
0.0
Published
2025-10-27
A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was informed early about a total of four security issues and confirmed that those have been fixed. However, the release notes on GitHub do not mention them.
CVSS Score
2.4
EPSS Score
0.001
Published
2025-10-05
Frappe Learning is a learning system that helps users structure their content. In versions 2.34.1 and below, there is a security vulnerability in Frappe Learning where the system did not adequately sanitize the content uploaded in the profile bio. Malicious SVG files could be used to execute arbitrary scripts in the context of other users.
CVSS Score
4.6
EPSS Score
0.0
Published
2025-09-17


Contact Us

Shodan ® - All rights reserved