CVE-2025-62158Medium· 5.3▾ SunlitFrappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially expos…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.
learning = 2.37.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62778Medium· 5.3Frappe Learning is a learning management system
CVE-2025-62779Medium· 5.4Frappe Learning is a learning system that helps users structure their content
CVE-2025-67734Medium· 5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2025-67730Medium· 5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2025-66581Medium· 6.5Frappe Learning Management System (LMS) is a learning system that helps users structure their content
CVE-2020-17527High· 7.5While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the…