Frappe Learning
cpe:2.3:a:frappe:frappe_lms:*:*:*:*:*:*:*
- 2.37.0
A vulnerability in Frappe Learning prior to version 2.38.0 allowed student-uploaded attachments in assignments to be stored as public files. This issue potentially exposed these files to anyone with the file URL, accessible without authentication. The vulnerability has been addressed in version 2.38.0, which changes the default storage setting for assignment attachments to private.
The vulnerability could lead to unauthorized access of student-uploaded files, allowing anyone with the file URL to view these attachments without authentication.
Users can update to Frappe Learning version 2.38.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.