Froxlor

Froxlor

58 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.73%
  • Veröffentlicht 16.01.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 07:36:57

Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.

Exploit
  • EPSS 97.65%
  • Veröffentlicht 16.01.2023 01:15:08
  • Zuletzt bearbeitet 21.11.2024 07:36:57

Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.

Exploit
  • EPSS 0.64%
  • Veröffentlicht 31.12.2022 10:15:13
  • Zuletzt bearbeitet 21.11.2024 07:36:06

Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 31.12.2022 09:15:12
  • Zuletzt bearbeitet 21.11.2024 07:36:06

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

Exploit
  • EPSS 0.48%
  • Veröffentlicht 30.12.2022 23:15:11
  • Zuletzt bearbeitet 21.11.2024 07:36:05

Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

Exploit
  • EPSS 1.3%
  • Veröffentlicht 05.11.2022 14:15:09
  • Zuletzt bearbeitet 21.11.2024 07:20:24

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.

  • EPSS 0.79%
  • Veröffentlicht 04.11.2022 13:15:10
  • Zuletzt bearbeitet 02.05.2025 19:15:53

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 28.08.2022 14:15:08
  • Zuletzt bearbeitet 21.11.2024 07:18:38

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.

Exploit
  • EPSS 1.41%
  • Veröffentlicht 13.04.2022 13:15:07
  • Zuletzt bearbeitet 21.11.2024 05:24:21

Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.

Exploit
  • EPSS 0.6%
  • Veröffentlicht 22.10.2021 20:15:10
  • Zuletzt bearbeitet 21.11.2024 05:23:22

Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the name, firstname, or username input fields.