Impact
Frappe Learning Management System allows an authenticated user to enter specially crafted content in certain editable fields that, when displayed in page metadata, causes a visitor’s browser to navigate to an attacker‑chosen URL. The flaw is an instance of HTML injection (CWE‑74) and also qualifies as a cross‑site scripting vulnerability (CWE‑79), allowing an attacker to introduce malicious markup that redirects users to an attacker‑chosen URL. The impact is limited to the browsers of users who view the affected pages; it does not allow remote code execution or compromise of the server itself.
Affected Systems
The vulnerability exists in Frappe LMS versions earlier than 2.53.0. Any installations of frappe:lms running a pre‑2.53.0 release are affected. Users of newer releases are not susceptible.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity. The EPSS score of 0.00136 (<1%) suggests a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Exploitation requires the attacker to be an authenticated user with author privileges and to navigate victim browsers to the manipulated content, making it moderate risk in environments where many users commonly view shared metadata.
OpenCVE Enrichment