CVE-2025-64705

F

rappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, users were able to access the submissions made by other students The issue has been fixed in version 2.41.0 by ensuring proper roles and redirecting if accessed via direct URL.

Configurations

Configuration 1 (hide)

cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*

History

17 Nov 2025, 19:21

Type Values Removed Values Added
First Time Frappe
Frappe learning
CPE cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*
References () https://github.com/frappe/lms/security/advisories/GHSA-qrvv-6g7r-g3v8 - () https://github.com/frappe/lms/security/advisories/GHSA-qrvv-6g7r-g3v8 - Vendor Advisory
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

12 Nov 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-12 23:15

Updated : 2025-11-17 19:21


NVD link : CVE-2025-64705

Mitre link : CVE-2025-64705

CVE.ORG link : CVE-2025-64705


JSON object : View

Products Affected
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo