PT-2025-46769 · Frappe · Frappe Learning

CVE-2025-64707

·

Published

2025-11-12

·

Updated

2025-11-13

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe Learning versions 2.0.0 through 2.40.9
Description Frappe Learning is a learning system used to structure content. A flaw exists where changes to user roles made by administrators were not immediately reflected due to caching mechanisms. This meant that a user might retain permissions after a role was revoked. The issue was addressed by clearing the cache after role updates.
Recommendations Update to version 2.41.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64707
GHSA-W2GF-RCHW-X6VM

Affected Products

Frappe Learning