Medium severity5.0NVD Advisory· Published Oct 5, 2025· Updated Apr 29, 2026
CVE-2025-11281
CVE-2025-11281
Description
A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. You should upgrade the affected component. The vendor was informed early about a total of four security issues and confirmed that those have been fixed. However, the release notes on GitHub do not mention them.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89nvdExploitThird Party Advisory
- gist.github.com/0xHamy/5ebd820ad30f33827011e9a614fb2f89nvdExploitThird Party Advisory
- vuldb.comnvdExploitThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.