CVE Explorer
CVE-2025-62158
Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"lms","vendor":"frappe","versions":[{"status":"affected","version":"< 2.38.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:661986f39cf3d5ac40e945e9e410e3552879b96bf343e89c9f1d6b4cc9f29c95 · sha256:fdcbc66116df8e7e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":2.7,"baseSeverity":"LOW","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:661986f39cf3d5ac40e945e9e410e3552879b96bf343e89c9f1d6b4cc9f29c95 · sha256:fdcbc66116df8e7e… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:661986f39cf3d5ac40e945e9e410e3552879b96bf343e89c9f1d6b4cc9f29c95 · sha256:fdcbc66116df8e7e… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/frappe/lms/commit/78640561f558a6c7396f8be48874f79a54f03420","tags":["x_refsource_MISC"],"url":"https://github.com/frappe/lms/commit/78640561f558a6c7396f8be48874f79a54f03420"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:661986f39cf3d5ac40e945e9e410e3552879b96bf343e89c9f1d6b4cc9f29c95 · sha256:fdcbc66116df8e7e… · /containers/cna/references/1
{"name":"https://github.com/frappe/lms/security/advisories/GHSA-h6fh-7f24-f2j5","tags":["x_refsource_CONFIRM"],"url":"https://github.com/frappe/lms/security/advisories/GHSA-h6fh-7f24-f2j5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:661986f39cf3d5ac40e945e9e410e3552879b96bf343e89c9f1d6b4cc9f29c95 · sha256:fdcbc66116df8e7e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.