PT-2025-46769 · Frappe · Frappe Learning

Published

2025-11-12

·

Updated

2025-11-13

·

CVE-2025-64707

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe Learning versions 2.0.0 through 2.40.9
Description Frappe Learning is a learning system used to structure content. A flaw exists where changes to user roles made by administrators were not immediately reflected due to caching mechanisms. This meant that a user might retain permissions after a role was revoked. The issue was addressed by clearing the cache after role updates.
Recommendations Update to version 2.41.0 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64707

Affected Products

Frappe Learning