PT-2025-50968 · Frappe · Frappe Learning Management System

Published

2025-12-12

·

Updated

2025-12-17

·

CVE-2025-67734

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Frappe Learning Management System (LMS) versions prior to 2.42.0
Description Frappe Learning Management System (LMS) allows authenticated attackers to inject JavaScript code through the Company Website field within the Job Form. This can lead to a cross-site scripting (XSS) attack, where the injected script executes in the browsers of users who view the malicious job posting. The vulnerable parameter is the Company Website field.
Recommendations Update to version 2.42.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-67734
GHSA-C495-QG4V-5VR7

Affected Products

Frappe Learning Management System