CVE-2023-42807: Frappe LMS SQL Injection Issue on People Page
Frappe LMS is an open source learning management system. In versions 1.0.0 and prior, on the People Page of LMS, there was an SQL Injection vulnerability. The issue has been fixed in the main branch. Users won't face this issue if they are using the latest main branch of the app.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42807?
CVE-2023-42807 is an SQL Injection vulnerability in Frappe LMS version 1.0.0 and prior on the People Page of LMS.
How severe is CVE-2023-42807?
CVE-2023-42807 has a severity rating of 9.8, which is classified as critical.
How can I fix CVE-2023-42807?
To fix CVE-2023-42807, make sure to update to the latest version of Frappe LMS from the main branch.
What is the affected software for CVE-2023-42807?
The affected software for CVE-2023-42807 is Frappe LMS version 1.0.0 and prior.
Where can I find more information about CVE-2023-42807?
More information about CVE-2023-42807 can be found at the following link: [https://github.com/frappe/lms/security/advisories/GHSA-wvq3-3wvp-6x63](https://github.com/frappe/lms/security/advisories/GHSA-wvq3-3wvp-6x63)