Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe frappe
Frappe frappe Lms |
|
| Vendors & Products |
Frappe frappe
Frappe frappe Lms |
Mon, 20 Oct 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe learning |
|
| CPEs | cpe:2.3:a:frappe:learning:2.37.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Frappe
Frappe learning |
|
| Metrics |
cvssV3_1
|
Fri, 10 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default. | |
| Title | Frappe had attachments made by students to their assignments of type Text set to public | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-10T20:05:38.107Z
Updated: 2025-10-10T20:44:13.136Z
Reserved: 2025-10-07T16:12:03.424Z
Link: CVE-2025-62158
Updated: 2025-10-10T20:44:08.862Z
Status : Analyzed
Published: 2025-10-10T20:15:39.213
Modified: 2025-10-20T17:18:16.573
Link: CVE-2025-62158
No data.
ReportizFlow