Vulnerabilities (CVE)

Filtered by vendor Froxlor Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-0572 1 Froxlor 1 Froxlor 2023-12-18 N/A 5.3 MEDIUM
Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-0566 1 Froxlor 1 Froxlor 2023-12-18 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.
CVE-2023-0565 1 Froxlor 1 Froxlor 2023-12-18 N/A 4.9 MEDIUM
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2020-28957 1 Froxlor 1 Froxlor 2021-10-28 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the name, firstname, or username input fields.
CVE-2020-10237 1 Froxlor 1 Froxlor 2021-07-21 2.1 LOW 5.5 MEDIUM
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at the right time, because of _createUserdataConf in install/lib/class.FroxlorInstall.php.
CVE-2020-10236 1 Froxlor 1 Froxlor 2020-03-09 3.6 LOW 6.1 MEDIUM
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, because of _createUserdataConf in install/lib/class.FroxlorInstall.php.