PT-2025-41602 · Frappe · Frappe Learning

0X.Hamy.1

·

Published

2025-10-10

·

Updated

2025-10-20

·

CVE-2025-62158

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frappe Learning versions prior to 2.38.0
Description Frappe Learning is a learning system used to structure content. Prior to version 2.38.0, student-uploaded assignment attachments were stored as public files, potentially exposing them to unauthorized access. Anyone possessing the file URL could access these files without authentication.
Recommendations Update to version 2.38.0 or later to ensure student-uploaded assignment attachments are stored as private files by default.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-62158
GHSA-H6FH-7F24-F2J5

Affected Products

Frappe Learning