Frappe Learning Management System
cpe:2.3:a:frappe:frappe_lms:*:*:*:*:*:*:*
- 2.0.0
A vulnerability in Frappe Learning Management System (LMS) versions prior to 2.44.0 allowed unauthorized users to access the full list of enrolled students' emails in batches. This issue has been addressed in version 2.44.0.
Exploitation of this vulnerability allowed unauthorized users to access sensitive information, specifically the emails of all students enrolled in a course, in batches.
Users can update to Frappe LMS version 2.44.0 or later to address this vulnerability. Instructions for updating can be found in the Frappe LMS GitHub repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.