CVE 2.7 LOW

Frappe had attachments made by students to their assignments of type Text set to public_CVE-2025-62158

2.7 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U

Description

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.

Basic Information

ID CVE-2025-62158
Source GitHub_M
Published Oct 10, 2025 at 20:05
Modified Oct 10, 2025 at 20:44

Affected Product

Vendor frappe
Product lms
Version < 2.38.0
Affected Versions frappe lms < 2.38.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.