CVE-2020-10235

HIGH

Froxlor < 0.10.14 - Remote Code Execution via Database Configuration Options

Title source: llm
STIX 2.1

Description

An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in install/lib/class.FroxlorInstall.php.

Scores

CVSS v3 8.8
EPSS 0.0168
EPSS Percentile 73.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-116
Status published
Products (2)
froxlor/froxlor < 0.10.14
froxlor/froxlor 0 - 0.10.14Packagist
Published Mar 09, 2020
Tracked Since Feb 18, 2026