Executive brief
Frappe Learning Management System (LMS) is a platform used to organize and deliver educational content. A security flaw allowed logged-in users to insert malicious code into certain text fields. When other people visit the affected pages, their browsers could be automatically redirected to a website chosen by the attacker, potentially leading to phishing or further malware exposure.
Technical details
An HTML injection vulnerability exists in Frappe LMS prior to version 2.53.0. The root cause is improper neutralization of special elements in user-editable fields that are subsequently rendered within page metadata. An authenticated attacker can exploit this by inputting crafted content that triggers a client-side redirect when viewed by other users. This requires network access and a low-privileged account, as well as interaction from a victim visiting the compromised page. The vulnerability is classified as CWE-74 and has been addressed in version 2.53.0.
Affected products
- Frappe Learning Management System (LMS) < 2.53.0
Timeline
- 2026-05-15: advisory: GitHub security advisory published
- 2026-06-10: disclosed: NVD publication date