Frappe Learning
cpe:2.3:a:frappe:frappe_lms:*:*:*:*:*:*:*
- <= 2.39.1
A vulnerability in Frappe Learning versions through 2.39.1 allows students to access the Quiz Form via direct URL. This access includes visibility of all quiz details, such as questions and answers.
Exploitation of this vulnerability allowed unauthorized access to quiz information, including all questions and answers.
The vulnerability has been patched in Frappe Learning version 2.40.1. Users should update to this version. Instructions for updating can be found in the Frappe Learning repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.