CVE detail
CVE-2023-42807 — CVE-2023-42807
Published 2023-09-21 · Modified 2026-06-17 · Vendor frappe · Product learning · Source nvd
MEDIUM
severity
CVSS-derived band
0.0035
EPSS probability
exploitation probability, 30d
28.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerability. The issue has been fixed in the `main` branch. Users won't face this issue if they are using the latest main branch of the app.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References