CVE-2023-42807
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
21/09/2023
Last modified:
03/10/2025
Description
Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerability. The issue has been fixed in the `main` branch. Users won't face this issue if they are using the latest main branch of the app.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:* | 1.0.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



