Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Frappe LMS enrollment bypass in paid courses via unrelated batch
Vulnerability Description
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
使用候选路径或通道进行的认证绕过
Vulnerability Title
Frappe Learning 授权问题漏洞
Vulnerability Description
Frappe lms是印度Frappe公司的学习管理系统。 Frappe Learning 2.51.0及之前版本存在授权问题漏洞,该漏洞源于支付验证绕过问题,可能导致用户通过使用无关批次绕过课程的支付验证。
CVSS Information
N/A
Vulnerability Type
N/A