Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Moderate
CVE-2023-0315
Disclosure Date: January 16, 2023 (last updated February 24, 2025)
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
3
Attacker Value
Unknown
CVE-2024-34070
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on the Login attempt, which will then be executed when viewed by the Administrator in the System Logs. By exploiting this vulnerability, the attacker can perform various malicious actions such as forcing the Administrator to execute actions without their knowledge or consent. For instance, the attacker can force the Administrator to add a new administrator controlled by the attacker, thereby giving the attacker full control over the application. This vulnerability is fixed in 2.1.9.
0
Attacker Value
Unknown
CVE-2023-50256
Disclosure Date: January 03, 2024 (last updated January 11, 2024)
Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory field requirements (e.g. surname, company name) established by the system. Version 2.1.2 fixes this issue.
0
Attacker Value
Unknown
CVE-2023-6069
Disclosure Date: November 10, 2023 (last updated November 16, 2023)
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
0
Attacker Value
Unknown
CVE-2023-4829
Disclosure Date: October 13, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.
0
Attacker Value
Unknown
CVE-2023-5564
Disclosure Date: October 13, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.
0
Attacker Value
Unknown
CVE-2023-4304
Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
0
Attacker Value
Unknown
CVE-2023-3668
Disclosure Date: July 14, 2023 (last updated February 25, 2025)
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
0
Attacker Value
Unknown
CVE-2023-3192
Disclosure Date: June 11, 2023 (last updated February 25, 2025)
Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.
0
Attacker Value
Unknown
CVE-2023-3173
Disclosure Date: June 09, 2023 (last updated February 25, 2025)
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
0