Frappe Learning
cpe:2.3:a:frappe:frappe_lms:*:*:*:*:*:*:*
- >= 2.0.0, <= 2.39.1
A vulnerability in Frappe Learning versions through 2.39.1 allows users to inject HTML into input fields within the Job Form. This unescaped HTML is subsequently executed on the job page, potentially leading to cross-site scripting (XSS) attacks.
Exploitation of this vulnerability allows for cross-site scripting (XSS) attacks, where injected HTML is executed as script code on the page.
Users can update to Frappe Learning version 2.40.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.