Vulnerabilities
Vulnerable Software
Frappe:  >> Learning  >> 1.0.0  Security Vulnerabilities
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side authorization logic allowed authenticated users to perform actions beyond their assigned roles across multiple features. Because the affected endpoints relied on client-side or UI-level checks instead of enforcing permissions on the server, users with low-privileged roles (such as students) could perform operations intended only for instructors or administrators via directly using the API's. This vulnerability is fixed in 2.41.0.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-12-05
Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.
CVSS Score
7.1
EPSS Score
0.001
Published
2023-10-12
Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerability. The issue has been fixed in the `main` branch. Users won't face this issue if they are using the latest main branch of the app.
CVSS Score
6.3
EPSS Score
0.0
Published
2023-09-21


Contact Us

Shodan ® - All rights reserved