Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.
History

Fri, 10 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Description Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.
Title Frappe had attachments made by students to their assignments of type Text set to public
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 2.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-10T20:05:38.107Z

Updated: 2025-10-10T20:44:13.136Z

Reserved: 2025-10-07T16:12:03.424Z

Link: CVE-2025-62158

cve-icon Vulnrichment

Updated: 2025-10-10T20:44:08.862Z

cve-icon NVD

Status : Received

Published: 2025-10-10T20:15:39.213

Modified: 2025-10-10T20:15:39.213

Link: CVE-2025-62158

cve-icon Redhat

No data.