Executive brief
Frappe LMS is a learning platform that helps organizations deliver structured training content. A path traversal vulnerability in its SCORM file renderer allows an attacker to read arbitrary files from the server, potentially exposing sensitive course materials, configuration data, or other confidential information stored on the system.
Technical details
A path traversal vulnerability exists in the SCORMRenderer.render method in lms/page_renderers.py. The renderer constructs and opens server-side file paths without validating that the resolved real path remains within the public/scorm directory. An unauthenticated remote attacker can request traversal paths (e.g., using ../ sequences) to read files outside the SCORM directory that are accessible to the server process. The vulnerability requires network access to the application but no authentication or user interaction. The fix, released in version 2.52.1, adds path validation to ensure all file access remains confined to the intended SCORM root directory.
Affected products
- Frappe Learning Management System before 2.52.1
Timeline
- 2026-09-17: disclosed
- 2026-04-09: patched: Fix merged in version 2.52.1