CVE-2026-39385
Vulnerability Description
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-288
Source
NVD
Vendor
frappe
Product
lms
Discussion (0)
Add Comment
No comments yet. Be the first!