CVE-2025-67730: Frappe authenticated users can execute XSS through form description fields
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields in the Job, Course and Batch forms. This issue is fixed in version 2.42.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67730?
CVE-2025-67730 has a medium severity rating due to the potential for cross-site scripting (XSS) attacks via malicious HTML and JavaScript.
How do I fix CVE-2025-67730?
To mitigate CVE-2025-67730, upgrade to Frappe Learning Management System version 2.42.0 or later.
Who is affected by CVE-2025-67730?
Authenticated users of Frappe Learning Management System versions prior to 2.42.0 are vulnerable to CVE-2025-67730.
What kind of attack can CVE-2025-67730 facilitate?
CVE-2025-67730 can facilitate cross-site scripting (XSS) attacks through the injection of malicious scripts in description fields.
When was CVE-2025-67730 discovered?
CVE-2025-67730 was reported and tracked alongside the release of affected versions prior to 2.42.0.