CVE-2020-27508: Frappe

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.

Affected products

  • Frappe Frappe: before 12.10.0 (fixed in 12.10.0)

Published 2020-12-11. Last modified 2026-06-17.