CVE-2025-11282 is a cross-site scripting (XSS) vulnerability affecting Frappe LMS versions 2.34.x and 2.35.0, stemming from an incomplete fix for a prior issue. With a CVSS score of 6.1 (Medium), it can be remotely exploited by a high-privileged attacker, potentially leading to high confidentiality and integrity impacts. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and it lacks specific exploit intelligence or significant community discussion. The vendor claims to have addressed this and other issues, though release notes do not reflect these fixes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.34.0, <= 2.35.0CPE matchmatch criteria | cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.