PT-2025-44054 · Frappe · Frappe Learning

Published

2025-10-27

·

Updated

2025-10-28

·

CVE-2025-62779

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe Learning versions prior to 2.39.1
Description Frappe Learning is a learning system designed to help users structure content. In versions prior to 2.39.1, users could add HTML through input fields within the Job Form. This allows for the injection of potentially malicious code via the Job Form input fields.
Recommendations Update Frappe Learning to version 2.39.1 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-62779
GHSA-J6H8-QG65-3FPX

Affected Products

Frappe Learning