PT-2026-34841 · Frappe · Press
T3L3Sc0P3
·
Published
2026-04-24
·
Updated
2026-04-30
·
CVE-2026-41317
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Press (affected versions not specified)
Description
Press, a Frappe custom app used for managing infrastructure, subscriptions, marketplace, and software-as-a-service (SaaS), contains a flaw in the 'press.api.account.create api secret' endpoint. This endpoint allows database writes and is accessible via the GET method, making it susceptible to Cross-Site Request Forgery (CSRF) style exploits, where an attacker could trick a user into performing unintended actions.
Recommendations
Restrict the 'press.api.account.create api secret' endpoint to only allow POST requests.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Press