Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-55006

Опубликовано: 09 авг. 2025
Источник: nvd
CVSS3: 4.3
CVSS3: 8.8
EPSS Низкий

Описание

Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScript or other potentially malicious content. Malicious SVG files could be used to execute arbitrary scripts in the context of other users. A fix for this issue is planned for version 2.34.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.34.0 (исключая)

EPSS

Процентиль: 21%
0.00066
Низкий

4.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo

EPSS

Процентиль: 21%
0.00066
Низкий

4.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo