Vulnerabilities
CVE-2024-34070
CRITICALFroxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on the Login attempt, which will then be executed when viewed by the Administrator in the System Logs. By exploiting this vulnerability, the attacker can perform various malicious actions such as forcing the Administrator to execute actions without their knowledge or consent. For instance, the attacker can force the Administrator to add a new administrator controlled by the attacker, thereby giving the attacker full control over the application. This vulnerability is fixed in 2.1.9.
CVE-2023-50256
HIGHFroxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory field requirements (e.g. surname, company name) established by the system. Version 2.1.2 fixes this issue.
CVE-2023-6069
CRITICALImproper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
CVE-2023-4829
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.
CVE-2023-5564
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.
CVE-2023-4304
LOWBusiness Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
CVE-2023-3668
CRITICALImproper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
CVE-2023-3192
MEDIUMSession Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.
CVE-2023-3172
MEDIUMPath Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.
CVE-2023-3173
CRITICALImproper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
CVE-2023-2666
MEDIUMAllocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.
CVE-2023-2034
CRITICALUnrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.
CVE-2023-1307
CRITICALAuthentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.
CVE-2023-1033
MEDIUMCross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11.
CVE-2023-0877
CRITICALCode Injection in GitHub repository froxlor/froxlor prior to 2.0.11.
CVE-2023-0671
CRITICALCode Injection in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-0564
MEDIUMWeak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-0566
MEDIUMImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.
CVE-2023-0565
MEDIUMBusiness Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-0572
MEDIUMUnchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-0315
HIGHCommand Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
CVE-2023-0316
MEDIUMPath Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.
CVE-2022-4867
LOWCross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
CVE-2022-4868
MEDIUMImproper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
CVE-2022-4864
MEDIUMArgument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
CVE-2022-3869
MEDIUMCode Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
CVE-2022-3721
HIGHCode Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
CVE-2022-3017
MEDIUMCross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.