PT-2025-46768 · Frappe · Frappe Learning

Published

2025-11-12

·

Updated

2025-11-13

·

CVE-2025-64705

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frappe Learning versions 2.0.0 through 2.40.9
Description Frappe Learning allows users to structure content. Versions 2.0.0 through 2.40.9 permitted users to access submissions made by other students. The issue was addressed in version 2.41.0 by enforcing proper roles and redirecting access attempts made via direct URL.
Recommendations Update to version 2.41.0 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-64705

Affected Products

Frappe Learning