CVE-2025-11281

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. You should upgrade the affected component. The vendor was informed early about a total of four security issues and confirmed that those have been fixed. However, the release notes on GitHub do not mention them.
References
Link Resource
https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89 Exploit Third Party Advisory
https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89#steps-to-reproduce Exploit Third Party Advisory
https://vuldb.com/?ctiid.327015 Permissions Required VDB Entry
https://vuldb.com/?id.327015 Third Party Advisory VDB Entry
https://vuldb.com/?submit.659695 Exploit Third Party Advisory VDB Entry
https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89 Exploit Third Party Advisory
https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89#steps-to-reproduce Exploit Third Party Advisory
https://vuldb.com/?submit.659695 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:frappe:learning:2.35.0:*:*:*:*:*:*:*

History

07 Oct 2025, 20:35

Type Values Removed Values Added
First Time Frappe
Frappe learning
References () https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89 - () https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89 - Exploit, Third Party Advisory
References () https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89#steps-to-reproduce - () https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89#steps-to-reproduce - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.327015 - () https://vuldb.com/?ctiid.327015 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.327015 - () https://vuldb.com/?id.327015 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.659695 - () https://vuldb.com/?submit.659695 - Exploit, Third Party Advisory, VDB Entry
CPE cpe:2.3:a:frappe:learning:2.35.0:*:*:*:*:*:*:*

07 Oct 2025, 19:15

Type Values Removed Values Added
References () https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89 - () https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89 -
References () https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89#steps-to-reproduce - () https://gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89#steps-to-reproduce -
References () https://vuldb.com/?submit.659695 - () https://vuldb.com/?submit.659695 -

05 Oct 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-05 04:15

Updated : 2025-10-07 20:35


NVD link : CVE-2025-11281

Mitre link : CVE-2025-11281

CVE.ORG link : CVE-2025-11281


JSON object : View

Products Affected

frappe

  • learning
CWE
CWE-266

Incorrect Privilege Assignment

CWE-284

Improper Access Control