Impact
A flaw in the enrollment process allowed a user to enroll in paid courses without completing payment by selecting a batch that was unrelated to the target course. The vulnerability effectively subverts the authorization check, granting access to paid content. This is an instance of authorization failure, identified as CWE-288.
Affected Systems
The issue exists in Frappe LMS versions 2.51.0 and earlier. Vendors and users should verify that they are not running these versions. The fix was released in version 2.52.0, which validates that the selected batch belongs to the requested course.
Risk and Exploitability
The reported CVSS score is 7.1, indicating a high severity impact. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack can be carried out by any user who has access to the course enrollment interface; thus, the risk is significant in environments where user access to the LMS is broad. An attacker can leverage this flaw to bypass payment friction and gain access to premium course material.
OpenCVE Enrichment