Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Users can circumvent 2FA login for users due to a lack of server side validation for the same. This vulnerability is fixed in commit ddb439f8eb1816010f2ef653a908648b71f9bba8.
CVSS
No CVSS.
References
Configurations
No configuration.
History
08 Jul 2025, 16:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-08 15:15
Updated : 2025-07-08 16:18
NVD link : CVE-2025-53545
Mitre link : CVE-2025-53545
CVE.ORG link : CVE-2025-53545
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication