A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was informed early about a total of four security issues and confirmed that those have been fixed. However, the release notes on GitHub do not mention them.
References
Link | Resource |
---|---|
https://gist.github.com/0xHamy/1f99795df9301a95ee0c6d18028cd3da | Exploit Third Party Advisory |
https://gist.github.com/0xHamy/1f99795df9301a95ee0c6d18028cd3da#steps-to-reproduce | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.327017 | Permissions Required VDB Entry |
https://vuldb.com/?id.327017 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.659697 | Exploit Third Party Advisory VDB Entry |
Configurations
History
07 Oct 2025, 20:37
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:frappe:learning:2.35.0:*:*:*:*:*:*:* | |
References | () https://gist.github.com/0xHamy/1f99795df9301a95ee0c6d18028cd3da - Exploit, Third Party Advisory | |
References | () https://gist.github.com/0xHamy/1f99795df9301a95ee0c6d18028cd3da#steps-to-reproduce - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.327017 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.327017 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.659697 - Exploit, Third Party Advisory, VDB Entry | |
First Time |
Frappe learning
Frappe |
05 Oct 2025, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-05 05:15
Updated : 2025-10-07 20:37
NVD link : CVE-2025-11283
Mitre link : CVE-2025-11283
CVE.ORG link : CVE-2025-11283
JSON object : View
Products Affected
frappe
- learning