CVE-2025-64707

Source
https://cve.org/CVERecord?id=CVE-2025-64707
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64707.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64707
Aliases
  • GHSA-w2gf-rchw-x6vm
Published
2025-11-12T22:27:54.937Z
Modified
2025-12-05T21:03:23.939207Z
Severity
  • 1.2 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Frappe LMS revoking access did not show immediate effect as roles were cached
Details

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins revoked a role from the user, the effect was not immediate because of caching. The issue has been fixed in version 2.41.0 by ensuring the cache is cleared after roles are updated.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64707.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-863"
    ]
}
References

Affected packages

Git / github.com/frappe/lms

Affected ranges

Type
GIT
Repo
https://github.com/frappe/lms
Events

Affected versions

v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.0
v2.10.0
v2.11.0
v2.12.0
v2.13.0
v2.14.0
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.23.0
v2.24.0
v2.25.0
v2.26.0
v2.27.0
v2.28.0
v2.28.1
v2.29.0
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.32.1
v2.32.2
v2.33.0
v2.34.0
v2.34.1
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.39.0
v2.39.1
v2.39.2
v2.4.0
v2.40.0
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64707.json"