Impact
The vulnerability is a path‑traversal flaw in the SCORM file rendering component of Frappe Learning Management System. An attacker can supply a crafted path that the renderer resolves without confirming it stays inside the public/scorm directory. This allows reading of arbitrary files on the server that the web process can access, leading to disclosure of potentially sensitive data. The flaw is rated CVSS 8.7, indicating a high severity impact.
Affected Systems
All instances of the frappe:lms product running a version earlier than 2.52.1 are affected. The patch was applied in version 2.52.1, making later releases immune.
Risk and Exploitability
The EPSS score of less than 1% suggests that, at the time of assessment, exploitation is unlikely, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, because it does not require authentication and can expose confidential files, organizations should consider the potential impact high. Attackers would need only the ability to send HTTP requests to the vulnerable SCORM endpoints to exploit the path traversal and read files on the server.
OpenCVE Enrichment