
A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan
CVE ID: CVE-2025-67730 Vulnerability Type: Stored Cross-Site Scripting (XSS) Severity: Medium–High (context-dependent)
This vulnerability allowed authenticated users to inject malicious HTML and JavaScript into description fields of Job, Course, and Batch forms. The injected payload would execute automatically in the browser of any user who later viewed the affected Job, Course, or Batch.
Because the payload is stored, the attack persists and affects every user who views the compromised content.
">
Steps to Reproduce:
2.42.0This issue was responsibly disclosed by Dharan Raghunathan.
This document is for educational and defensive security purposes only.