CVE-2026-46546

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Frappe Learning Management System (LMS) es un sistema de aprendizaje que ayuda a los usuarios a estructurar su contenido. Antes de la versión 2.53.0, un usuario autenticado podía proporcionar contenido especialmente diseñado en ciertos campos editables por el usuario que, al aparecer en los metadatos de la página, hacía que los navegadores de los visitantes navegaran a una URL elegida por el atacante. Este problema ha sido parcheado en la versión 2.53.0.

09 Jul 2026, 16:29

Type Values Removed Values Added
References () https://github.com/frappe/lms/security/advisories/GHSA-2x47-gr9q-w6fv - () https://github.com/frappe/lms/security/advisories/GHSA-2x47-gr9q-w6fv - Vendor Advisory
First Time Frappe
Frappe learning
CPE cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79

10 Jun 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 01:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-46546

Mitre link : CVE-2026-46546

CVE.ORG link : CVE-2026-46546


JSON object : View

Products Affected

frappe

  • learning
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')