CVE-2024-50356
Last modified
CVE-2024-50356 is a none-severity vulnerability. Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn't be able to login by bypassing the 2FA. Only users who have enabled 2FA are affected. Commit ba0007c28ac814260f836849bc07d29beea7deb6 patches this bug.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-50356?
How severe is CVE-2024-50356?
How do I fix CVE-2024-50356?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-50350LibreNMS is an open-source, PHP/MySQL/SNMP-based network mon…5.4
- CVE-2024-50351LibreNMS is an open-source, PHP/MySQL/SNMP-based network mon…5.4
- CVE-2024-50352LibreNMS is an open-source, PHP/MySQL/SNMP-based network mon…5.4
- CVE-2024-50353ICG.AspNetCore.Utilities.CloudStorage is a collection of clo…5.3
- CVE-2024-50354gnark is a fast zk-SNARK library that offers a high-level AP…5.5
- CVE-2024-50355LibreNMS is an open-source, PHP/MySQL/SNMP-based network mon…4.8
- CVE-2024-50357FutureNet NXR series routers provided by Century Systems Co.…9.8
- CVE-2024-50358A CWE-15 "External Control of System or Configuration Settin…7.2
- CVE-2024-50359A CWE-78 "Improper Neutralization of Special Elements used i…7.2
- CVE-2024-5036The Sina Extension for Elementor (Slider, Gallery, Form, Mod…5.4
- CVE-2024-50360A CWE-78 "Improper Neutralization of Special Elements used i…7.2
- CVE-2024-50361A CWE-78 "Improper Neutralization of Special Elements used i…7.2
Are you affected by CVE-2024-50356?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
