Vulnerability in Frappe Learning Management System Affects Quiz Score Integrity
CVE-2026-39415

5.3MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-39415?

The Frappe Learning Management System (LMS) has a client-side vulnerability that allows students to modify their quiz scores before submission. Prior to version 2.46.0, the application calculated scores on the client side, enabling alterations through browser developer tools. While this vulnerability does not permit data modification of other users or escalate privileges, it significantly undermines the integrity of quiz results, thereby affecting academic reliability. This issue highlights the need for robust server-side validation to ensure data integrity and protect the academic framework.

Affected Version(s)

lms < 2.46.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.