Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Froxlor MEDIUM 6.1
CVE-2020-29653

Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected …

Fix: after 0.10.22
Fix from $1,600 2022-04-13
Froxlor MEDIUM 5.4
CVE-2020-28957

Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts o…

No fix yet
Fix from $1,600 2021-10-22
Froxlor CRITICAL 9.8
CVE-2021-42325EPSS 12%

Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

Fix: 0.10.30+
Fix from $2,300 2021-10-12
Froxlor HIGH 8.8
CVE-2020-10235

An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via th…

Fix: 0.10.14+
Fix from $1,950 2020-03-09
Froxlor MEDIUM 6.1
CVE-2020-10236

An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was n…

Fix: 0.10.14+
Fix from $1,600 2020-03-09
Froxlor MEDIUM 5.5
CVE-2020-10237

An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting prop…

Fix: after 0.10.15
Fix from $1,600 2020-03-09
Froxlor HIGH 7.2
CVE-2018-1000527

Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and …

Fix: after 0.9.39.5
Fix from $1,950 2018-06-26
Froxlor HIGH 7.5
CVE-2018-12642

Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.

Fix: after 0.9.39.5
Fix from $1,950 2018-06-22
Froxlor CRITICAL 9.8
CVE-2015-5959

Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.…

Fix: after 0.9.33.1
Fix from $2,300 2017-09-06
Froxlor CRITICAL 9.8
CVE-2016-5100

Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset…

Fix: after 0.9.34.2
Fix from $2,300 2017-02-13