Low severity2.4NVD Advisory· Published Oct 5, 2025· Updated Apr 29, 2026
CVE-2025-11283
CVE-2025-11283
Description
A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was informed early about a total of four security issues and confirmed that those have been fixed. However, the release notes on GitHub do not mention them.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- gist.github.com/0xHamy/1f99795df9301a95ee0c6d18028cd3danvdExploitThird Party Advisory
- gist.github.com/0xHamy/1f99795df9301a95ee0c6d18028cd3danvdExploitThird Party Advisory
- vuldb.comnvdExploitThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.