Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL.
References
| Link | Resource |
|---|---|
| https://github.com/frappe/lms/commit/8749e21744547ae32f729bde05c854113e126750 | Patch |
| https://github.com/frappe/lms/security/advisories/GHSA-8xvv-6v89-xxgx | Vendor Advisory |
Configurations
History
03 Nov 2025, 18:40
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Frappe learning
Frappe |
|
| References | () https://github.com/frappe/lms/commit/8749e21744547ae32f729bde05c854113e126750 - Patch | |
| References | () https://github.com/frappe/lms/security/advisories/GHSA-8xvv-6v89-xxgx - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CPE | cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:* |
27 Oct 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-27 22:15
Updated : 2025-11-03 18:40
NVD link : CVE-2025-62778
Mitre link : CVE-2025-62778
CVE.ORG link : CVE-2025-62778
JSON object : View
Products Affected
frappe
- learning
CWE
CWE-425
Direct Request ('Forced Browsing')
