Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.
References (2)
Core 2
Core References
Patch, Third Party Advisory
https://github.com/froxlor/froxlor/commit/bd5b99dc1c06f594b9563d459a50bf3b32504876
Exploit, Issue Tracking, Patch, Third Party Advisory
https://huntr.dev/bounties/8339e4f1-d430-4845-81b5-36dd9fcdac49
Scores
CVSS v3
6.2
EPSS
0.0030
EPSS Percentile
53.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (2)
froxlor/froxlor
< 2.0.10
froxlor/froxlor
0 - 2.0.10Packagist
Published
Jan 29, 2023
Tracked Since
Feb 18, 2026