Impact
Frappe Learning Management System contains a stored cross‑site scripting flaw that allows malicious scripts to be persisted in user input fields and later rendered without escaping. This weakness, identified as CWE‑79, can enable an attacker to execute arbitrary JavaScript in the browser of any user who views the affected data. The potential consequences include session hijacking, credential theft, data manipulation, or defacement of the application, ultimately compromising confidentiality, integrity, and availability of user information.
Affected Systems
The vulnerability is present in Frappe LMS releases from version 2.27.0 up to, but not including, version 2.48.0. All installations within this range may expose multiple data entry points that store and display user-generated content. The flaw was fixed in version 2.48.0 and later releases.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited or no active exploitation. The likely attack vector involves an attacker injecting malicious payloads via untrusted input fields that are subsequently rendered for other users. No privileged access is required, meaning the vulnerability can affect all users with content submission permissions.
OpenCVE Enrichment