CVE-2026-23497 describes a stored Cross-Site Scripting (XSS) vulnerability in Frappe Learning Management System (LMS) versions 2.44.0 and earlier. An authenticated attacker can inject malicious JavaScript by crafting a specially named image file, which then executes when rendered on course or jobs pages. This vulnerability is rated Medium severity (CVSS 5.4), requiring user interaction and low privileges for exploitation, with potential impacts on confidentiality and integrity. The attack vector is network-based, but the attack complexity is low. Currently, there is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.45.0CPE matchmatch criteria | cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.