CVE-2026-39385
HIGHFrappe LMS enrollment bypass in paid courses via unrelated batch
Title source: cnaDescription
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/frappe/lms/security/advisories/GHSA-c4xh-2rcm-6mgc
Scores
CVSS v4
7.1
EPSS
0.0022
EPSS Percentile
12.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-288
Status
published
Products (1)
frappe/lms
<= 2.51.0
Published
Jul 20, 2026
Tracked Since
Jul 20, 2026