CVE-2025-11281

MEDIUM

Frappe LMS 2.35.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. You should upgrade the affected component. The vendor was informed early about a total of four security issues and confirmed that those have been fixed. However, the release notes on GitHub do not mention them.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.327015
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.327015
Exploit, Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.659695

Scores

CVSS v3 5.0
EPSS 0.0032
EPSS Percentile 23.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-284
Status published
Products (1)
frappe/learning 2.35.0
Published Oct 05, 2025
Tracked Since Feb 18, 2026