Frappe Learning
cpe:2.3:a:frappe:frappe_lms:*:*:*:*:*:*:*
- <= 2.34.1
A vulnerability exists in Frappe Learning versions 2.34.1 and below, where the profile bio content was not properly sanitized. This oversight allowed users to upload malicious SVG files that could execute arbitrary scripts in the context of other users.
Exploitation of this vulnerability could lead to the execution of arbitrary scripts in the context of other users.
The vulnerability has been addressed in version 2.35.0. Users should update to this version to mitigate the issue.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.