CVE-2025-64705

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, users were able to access the submissions made by other students The issue has been fixed in version 2.41.0 by ensuring proper roles and redirecting if accessed via direct URL.
Configurations

Configuration 1 (hide)

cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*

History

17 Nov 2025, 19:21

Type Values Removed Values Added
First Time Frappe
Frappe learning
CPE cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
References () https://github.com/frappe/lms/security/advisories/GHSA-qrvv-6g7r-g3v8 - () https://github.com/frappe/lms/security/advisories/GHSA-qrvv-6g7r-g3v8 - Vendor Advisory
CWE NVD-CWE-noinfo

12 Nov 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-12 23:15

Updated : 2025-11-17 19:21


NVD link : CVE-2025-64705

Mitre link : CVE-2025-64705

CVE.ORG link : CVE-2025-64705


JSON object : View

Products Affected

frappe

  • learning
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo