LMS
frappe/lms
Easy to Use, 100% Open Source Learning Management System
#courses-management-system#education#frappe#learning-management-system#lms#javascript#learning#online-learning#open-source#python#online-course-platform#hacktoberfest
スコア
55
/ 100
Star
2,910
Fork
1,299
Open Issue
70
サイズ
98MB
言語
Vue
最終push
0 日前
Docker
—
採点内訳
過去CVE 18件 (やや多い)
✓直近 push: 0 日前
✓得意言語 (Vue)
—オープンissue 70件
—中規模 (98MB)
✓Docker 未対応
—1k–10k: 初心者ベスト (★2,910)
✓※ 各項目の重みは「採点ルール」を参照。合計は 0 で底打ち。
過去の SecurityAdvisory (18 件)
- HTML injection in user-controlled metadata
- Path transversal in SCORM
- Client-Side Manipulation of Quiz Scores
- Stored XSS in Frappe LMS
- Unauthorized users were able to get details of unpublished courses
- Unauthorised user was able to access the full list of batch enrolled students
- Stored XSS via Unsanitized Image Filename in Course and Jobs Pages
- JavaScript was being executed through the Company Website field input of Job Form
- HTML and JavaScript injection in description fields
- Missing Server-Side Authorization in Business Logic
- Revoking access did not show immediate effect as roles were cached
- User was able to access the submission of other students
- Users were able to add HTML through input fields in the Job Form
- Students were able to access the Quiz Form via direct URL
- Attachments made by students to their assignments of type Text were public
- Potential for Malicious Content upload via Profile bio field
- Potential for Malicious SVG Upload in Image Upload Feature
- Frappe LMS SQL Injection Issue on People Page