Описание
Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerability. The issue has been fixed in the main branch. Users won't face this issue if they are using the latest main branch of the app.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.0 (включая)
cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00045
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 6.3
github
больше 2 лет назад
Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerability. The issue has been fixed in the `main` branch. Users won't face this issue if they are using the latest main branch of the app.
EPSS
Процентиль: 13%
0.00045
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-89