Vulnerability in Frappe Learning Management System Affects Quiz Score Integrity
CVE-2026-39415
5.3MEDIUM
What is CVE-2026-39415?
The Frappe Learning Management System (LMS) has a client-side vulnerability that allows students to modify their quiz scores before submission. Prior to version 2.46.0, the application calculated scores on the client side, enabling alterations through browser developer tools. While this vulnerability does not permit data modification of other users or escalate privileges, it significantly undermines the integrity of quiz results, thereby affecting academic reliability. This issue highlights the need for robust server-side validation to ensure data integrity and protect the academic framework.
Affected Version(s)
lms < 2.46.0
