Frappe Learning Public File Exposure Vulnerability in Assignment Attachments

Vulnerability

A vulnerability in Frappe Learning prior to version 2.38.0 allowed student-uploaded attachments in assignments to be stored as public files. This issue potentially exposed these files to anyone with the file URL, accessible without authentication. The vulnerability has been addressed in version 2.38.0, which changes the default storage setting for assignment attachments to private.

Impact

The vulnerability could lead to unauthorized access of student-uploaded files, allowing anyone with the file URL to view these attachments without authentication.

Remediation

Users can update to Frappe Learning version 2.38.0 or later, where this vulnerability has been fixed.

Added: Oct 10, 2025, 8:18 PM
Updated: Oct 10, 2025, 8:18 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
8.2
remediation
7.7
relevance
0.7
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.