Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScript or other potentially malicious content. Malicious SVG files could be used to execute arbitrary scripts in the context of other users. A fix for this issue is planned for version 2.34.0.
Metrics
Affected Vendors & Products
References
History
Mon, 11 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 09 Aug 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScript or other potentially malicious content. Malicious SVG files could be used to execute arbitrary scripts in the context of other users. A fix for this issue is planned for version 2.34.0. | |
Title | Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Feature | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-09T02:01:57.136Z
Updated: 2025-08-11T14:49:39.107Z
Reserved: 2025-08-04T17:34:24.421Z
Link: CVE-2025-55006

Updated: 2025-08-11T14:49:22.084Z

Status : Awaiting Analysis
Published: 2025-08-09T03:15:47.177
Modified: 2025-08-11T18:32:48.867
Link: CVE-2025-55006

No data.