{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-11283","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-10-04T09:22:39.244Z","datePublished":"2025-10-05T05:02:06.329Z","dateUpdated":"2025-10-06T20:07:29.456Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-10-05T05:02:06.329Z"},"title":"Frappe LMS Course cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"Cross Site Scripting"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]}],"affected":[{"vendor":"Frappe","product":"LMS","versions":[{"version":"2.35.0","status":"affected"}],"modules":["Course Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was informed early about a total of four security issues and confirmed that those have been fixed. However, the release notes on GitHub do not mention them."},{"lang":"de","value":"Es wurde eine Schwachstelle in Frappe LMS 2.35.0 entdeckt. Es geht hierbei um eine nicht näher spezifizierte Funktion der Komponente Course Handler. Mittels dem Manipulieren des Arguments Description mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Die Schwachstelle wurde öffentlich offengelegt und könnte ausgenutzt werden. Es wird geraten, die betroffene Komponente zu aktualisieren."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":4.8,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":2.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":2.4,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":3.3,"vectorString":"AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:OF/RC:C"}}],"timeline":[{"time":"2025-10-04T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-10-04T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-10-04T11:28:19.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"0xHamy (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.327017","name":"VDB-327017 | Frappe LMS Course cross site scripting","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.327017","name":"VDB-327017 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.659697","name":"Submit #659697 | Frappe Frappe LMS 2.35.0 Cross Site Scripting","tags":["third-party-advisory"]},{"url":"https://gist.github.com/0xHamy/1f99795df9301a95ee0c6d18028cd3da","tags":["related"]},{"url":"https://gist.github.com/0xHamy/1f99795df9301a95ee0c6d18028cd3da#steps-to-reproduce","tags":["exploit"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-06T20:07:21.780373Z","id":"CVE-2025-11283","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-06T20:07:29.456Z"}}]}}