CVE-2025-62158 - CVE House
Back to Database
Status published Low CVE-2025-62158

Frappe had attachments made by students to their assignments of type Text set to public

Vulnerability Description

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62158

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

lms
Vulnerable Versions:
< 2.38.0

Timeline

Official Publish: October 10th, 2025
Last Modified: October 10th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)