CVE-2025-62158

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.
Configurations

Configuration 1 (hide)

cpe:2.3:a:frappe:learning:2.37.0:*:*:*:*:*:*:*

History

20 Oct 2025, 17:18

Type Values Removed Values Added
References () https://github.com/frappe/lms/commit/78640561f558a6c7396f8be48874f79a54f03420 - () https://github.com/frappe/lms/commit/78640561f558a6c7396f8be48874f79a54f03420 - Patch
References () https://github.com/frappe/lms/security/advisories/GHSA-h6fh-7f24-f2j5 - () https://github.com/frappe/lms/security/advisories/GHSA-h6fh-7f24-f2j5 - Mitigation, Vendor Advisory
CPE cpe:2.3:a:frappe:learning:2.37.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Frappe learning
Frappe

10 Oct 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-10 20:15

Updated : 2025-10-20 17:18


NVD link : CVE-2025-62158

Mitre link : CVE-2025-62158

CVE.ORG link : CVE-2025-62158


JSON object : View

Products Affected

frappe

  • learning
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor