CVE 2.7 LOW

Press vulnerable to email flooding to users due to lack of validation and rate limits_CVE-2025-59421

2.7 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U

Description

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). A bad actor can flood the inbox of a user by repeatedly sending invites (duplicate). The issue is fixed in commit 83c3fc7676c5dbbe1fd5092d21d95a10c7b48615.

Basic Information

ID CVE-2025-59421
Source GitHub_M
Published Sep 18, 2025 at 14:42

Affected Product

Vendor frappe
Product press
Version < 83c3fc7676c5dbbe1fd5092d21d95a10c7b48615
Affected Versions frappe press < 83c3fc7676c5dbbe1fd5092d21d95a10c7b48615

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.