CVE-2025-62778

Severity CVSS v4.0:
LOW
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
27/10/2025
Last modified:
03/11/2025

Description

Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:* 2.0.0 (including) 2.39.2 (excluding)