Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user inpu…
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full emai…
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does…
Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quo…
Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whit…
Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supp…
Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS ena…
Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disable…
Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows …
Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to cr…
Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fie…
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.
Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.
Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.
Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.
Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11.
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.
Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.
Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.
Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.