We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-53545

Press has a potential 2FA bypass



Description

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Users can circumvent 2FA login for users due to a lack of server side validation for the same. This vulnerability is fixed in commit ddb439f8eb1816010f2ef653a908648b71f9bba8.

Reserved 2025-07-02 | Published 2025-07-08 | Updated 2025-07-08 | Assigner GitHub_M


MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-287: Improper Authentication

Product status

< ddb439f8eb1816010f2ef653a908648b71f9bba8
affected

References

github.com/.../press/security/advisories/GHSA-fwfh-vhjg-45q4

github.com/...ommit/ddb439f8eb1816010f2ef653a908648b71f9bba8

cve.org (CVE-2025-53545)

nvd.nist.gov (CVE-2025-53545)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-53545

Support options

Helpdesk Chat, Email, Knowledgebase