PT-2025-40792 · Frappe · Frappe Lms
0Xhamy
·
Published
2025-10-05
·
Updated
2025-10-05
·
CVE-2025-11281
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Frappe LMS version 2.35.0
Description
A flaw exists in Frappe LMS that allows for improper access controls. The issue is related to an unknown function within the
/courses/ file of the Unpublished Course Handler component. The attack can be initiated remotely and is considered difficult to exploit. The exploit has been publicly disclosed.Recommendations
Upgrade the affected component.
Exploit
Fix
Improper Access Control
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frappe Lms