CVE-2025-67734 MEDIUM

CVE-2025-67734: Frappe Authenticated Users can Execute JavaScript through its Job Form

Vendor Frappe
Product lms
Weakness CWE-79 · XSS
Published December 12, 2025
Last update December 12, 2025

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

Description

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposing users to an XSS attack. The script could then be executed in the browsers of users who opened the malicious job posting. This issue is fixed in version 2.42.0.

Key dates

Disclosure timeline

December 12, 2025 CVE published
December 12, 2025 Record updated