Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.
History

Tue, 21 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Frappe frappe
Frappe frappe Lms
Vendors & Products Frappe frappe
Frappe frappe Lms

Mon, 20 Oct 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Frappe
Frappe learning
CPEs cpe:2.3:a:frappe:learning:2.37.0:*:*:*:*:*:*:*
Vendors & Products Frappe
Frappe learning
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Fri, 10 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Description Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.
Title Frappe had attachments made by students to their assignments of type Text set to public
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 2.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-10T20:05:38.107Z

Updated: 2025-10-10T20:44:13.136Z

Reserved: 2025-10-07T16:12:03.424Z

Link: CVE-2025-62158

cve-icon Vulnrichment

Updated: 2025-10-10T20:44:08.862Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-10T20:15:39.213

Modified: 2025-10-20T17:18:16.573

Link: CVE-2025-62158

cve-icon Redhat

No data.