CyberRota Analysis
AI-GeneratedFrappe LMS versions 2.51.0 and earlier are vulnerable to a payment validation bypass, allowing users to enroll in courses without proper payment by exploiting unrelated batches. This flaw could lead to unauthorized access to course materials and potential revenue loss for educational institutions. Organizations using affected versions should prioritize upgrading to 2.52.0 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.