CVE 5.1 MEDIUM

Frappe authenticated users can execute XSS through form description fields_CVE-2025-67730

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields in the Job, Course and Batch forms. This issue is fixed in version 2.42.0.

Basic Information

ID CVE-2025-67730
Source GitHub_M
Published Dec 12, 2025 at 07:23

Affected Product

Vendor frappe
Product lms
Version < 2.42.0
Affected Versions frappe lms < 2.42.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.