Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

0X.Hamy.1

#48398of 53,633
5.3Total CVSS
Vulnerabilities · 1
PT-2025-41602
5.3
2025-10-10
Frappe · Frappe Learning · CVE-2025-62158
**Name of the Vulnerable Software and Affected Versions** Frappe Learning versions prior to 2.38.0 **Description** Frappe Learning is a learning system used to structure content. Prior to version 2.38.0, student-uploaded assignment attachments were stored as public files, potentially exposing them to unauthorized access. Anyone possessing the file URL could access these files without authentication. **Recommendations** Update to version 2.38.0 or later to ensure student-uploaded assignment attachments are stored as private files by default.