Loading HuntDB...

Vulnerabilities

CVE-2024-34070

CRITICAL

Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on the Login attempt, which will then be executed when viewed by the Administrator in the System Logs. By exploiting this vulnerability, the attacker can perform various malicious actions such as forcing the Administrator to execute actions without their knowledge or consent. For instance, the attacker can force the Administrator to add a new administrator controlled by the attacker, thereby giving the attacker full control over the application. This vulnerability is fixed in 2.1.9.

Published May 10, 2024

CVE-2023-50256

HIGH

Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory field requirements (e.g. surname, company name) established by the system. Version 2.1.2 fixes this issue.

Published Jan 03, 2024

CVE-2023-6069

CRITICAL

Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.

Published Nov 10, 2023

CVE-2023-4829

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.

Published Oct 13, 2023

CVE-2023-5564

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.

Published Oct 13, 2023

CVE-2023-4304

LOW

Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.

Published Aug 11, 2023

CVE-2023-3668

CRITICAL

Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.

Published Jul 14, 2023

CVE-2023-3192

MEDIUM

Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.

Published Jun 11, 2023

CVE-2023-3172

MEDIUM

Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.

Published Jun 09, 2023

CVE-2023-3173

CRITICAL

Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.

Published Jun 09, 2023

CVE-2023-2666

MEDIUM

Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.

Published May 12, 2023

CVE-2023-2034

CRITICAL

Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.

Published Apr 14, 2023

CVE-2023-1307

CRITICAL

Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.

Published Mar 10, 2023

CVE-2023-1033

MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11.

Published Feb 25, 2023

CVE-2023-0877

CRITICAL

Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.

Published Feb 17, 2023

CVE-2023-0671

CRITICAL

Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.

Published Feb 04, 2023

CVE-2023-0564

MEDIUM

Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.

Published Jan 29, 2023

CVE-2023-0566

MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.

Published Jan 29, 2023

CVE-2023-0565

MEDIUM

Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.

Published Jan 29, 2023

CVE-2023-0572

MEDIUM

Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.

Published Jan 29, 2023

CVE-2023-0315

HIGH

Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.

Published Jan 16, 2023

CVE-2023-0316

MEDIUM

Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.

Published Jan 16, 2023

CVE-2022-4867

LOW

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

Published Dec 31, 2022

CVE-2022-4868

MEDIUM

Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

Published Dec 31, 2022

CVE-2022-4864

MEDIUM

Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

Published Dec 30, 2022

CVE-2022-3869

MEDIUM

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.

Published Nov 05, 2022

CVE-2022-3721

HIGH

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

Published Nov 04, 2022

CVE-2022-3017

MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.

Published Aug 28, 2022