CVE-2026-41430 - Press vulnerable to reflected XSS on login redirection
CVE ID :CVE-2026-41430
Published : April 24, 2026, 4:16 a.m. | 1 hour, 57 minutes ago
Description :Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected XSS. The patch in commit 16d1b6ca2559f858a1de77bcb03fd7f1b81671c6 fixes the issue by restricting redirects to internal URLs only.
Severity: 1.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 24, 2026, 4:16 a.m. | 1 hour, 57 minutes ago
Description :Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected XSS. The patch in commit 16d1b6ca2559f858a1de77bcb03fd7f1b81671c6 fixes the issue by restricting redirects to internal URLs only.
Severity: 1.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...