CVE-2025-62779

Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML through input fields in the Job Form.
Configurations

Configuration 1 (hide)

cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*

History

03 Nov 2025, 18:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*
References () https://github.com/frappe/lms/commit/75001b494d5d8198eab20b0cd85d5bd719448ea3 - () https://github.com/frappe/lms/commit/75001b494d5d8198eab20b0cd85d5bd719448ea3 - Patch
References () https://github.com/frappe/lms/security/advisories/GHSA-j6h8-qg65-3fpx - () https://github.com/frappe/lms/security/advisories/GHSA-j6h8-qg65-3fpx - Vendor Advisory
First Time Frappe learning
Frappe

27 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-27 22:15

Updated : 2025-11-03 18:38


NVD link : CVE-2025-62779

Mitre link : CVE-2025-62779

CVE.ORG link : CVE-2025-62779


JSON object : View

Products Affected

frappe

  • learning
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')