Frappe Learning Management System
cpe:2.3:a:frappe:frappe_lms:*:*:*:*:*:*:*
- >= 2.0.0, <= 2.44.0
A vulnerability exists in Frappe Learning Management System (LMS) versions 2.44.0 and prior, allowing unauthorized users to access details of unpublished courses through API endpoints. This issue is set to be addressed in the upcoming 2.45.0 release.
The vulnerability enables unauthorized access to information about unpublished courses via API endpoints.
Users can upgrade to Frappe LMS version 2.45.0, where this issue has been fixed. In the patched version, the endpoint verifies the publication status of the course, ensuring that only admins and enrolled students can access the details.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.