PT-2026-34848 · Frappe · Press
T3L3Sc0P3
·
Published
2026-04-24
·
Updated
2026-04-30
·
CVE-2026-41430
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Press (affected versions not specified)
Description
Press is a Frappe custom app used for managing infrastructure, subscriptions, marketplace, and software-as-a-service (SaaS) on Frappe Cloud. The redirect parameter on the login page is susceptible to reflected Cross-Site Scripting (XSS), a flaw where an application includes untrusted data in a web page without proper validation, allowing an attacker to execute scripts in the victim's browser.
Recommendations
Restrict redirects to internal URLs only to prevent the execution of malicious scripts via the redirect parameter.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Press