Frappe · Frappe Lms · CVE-2026-39415
**Name of the Vulnerable Software and Affected Versions**
Frappe Learning Management System (LMS) versions prior to 2.46.0
**Description**
Students can modify quiz scores before submission because the application relies on client-side calculated scores. These values can be altered using browser developer tools before the submission request is sent, compromising the integrity of quiz results and academic reliability. This issue affects data integrity but does not allow privilege escalation, unauthorized access to other accounts, or the exposure of confidential information.
**Recommendations**
Update to version 2.46.0.