NONE · 0

CVE-2026-39405

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to...

Vulnerability Description

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-39405?

CVE-2026-39405 is a documented vulnerability. Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to...

How severe is CVE-2026-39405?

CVSS scoring is not yet available for CVE-2026-39405. Check NVD for updates.

Is there a patch for CVE-2026-39405?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.