Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Moderate

CVE-2023-0315

Disclosure Date: January 16, 2023 (last updated February 24, 2025)
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
Attacker Value
Unknown

CVE-2024-34070

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on the Login attempt, which will then be executed when viewed by the Administrator in the System Logs. By exploiting this vulnerability, the attacker can perform various malicious actions such as forcing the Administrator to execute actions without their knowledge or consent. For instance, the attacker can force the Administrator to add a new administrator controlled by the attacker, thereby giving the attacker full control over the application. This vulnerability is fixed in 2.1.9.
0
Attacker Value
Unknown

CVE-2023-50256

Disclosure Date: January 03, 2024 (last updated January 11, 2024)
Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory field requirements (e.g. surname, company name) established by the system. Version 2.1.2 fixes this issue.
Attacker Value
Unknown

CVE-2023-6069

Disclosure Date: November 10, 2023 (last updated November 16, 2023)
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
Attacker Value
Unknown

CVE-2023-4829

Disclosure Date: October 13, 2023 (last updated October 18, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.
Attacker Value
Unknown

CVE-2023-5564

Disclosure Date: October 13, 2023 (last updated October 18, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.
Attacker Value
Unknown

CVE-2023-4304

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
Attacker Value
Unknown

CVE-2023-3668

Disclosure Date: July 14, 2023 (last updated February 25, 2025)
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
Attacker Value
Unknown

CVE-2023-3192

Disclosure Date: June 11, 2023 (last updated February 25, 2025)
Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.
Attacker Value
Unknown

CVE-2023-3173

Disclosure Date: June 09, 2023 (last updated February 25, 2025)
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.