CVE-2025-48958

MEDIUM

Froxlor <2.2.6 - XSS

Title source: llm
STIX 2.1

Description

Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks, credential theft, and reputational damage by redirecting users to malicious external websites. The vulnerability has a medium severity, as it can be exploited through user input without authentication. Version 2.2.6 fixes the issue.

Scores

CVSS v3 5.5
EPSS 0.0017
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
froxlor/froxlor < 2.2.6
froxlor/froxlor 0 - 2.2.6Packagist
Published Jun 02, 2025
Tracked Since Feb 18, 2026