Multiple critical vulnerabilities in Froxlor, including Cross-Site Scripting and SQL Injection flaws, allow remote attackers to bypass security controls, manipulate data, and disclose sensitive information. The CVSS Base Score for these issues is 9.9 (Critical). Affected are all open-source Froxlor versions prior to 2.3.8, and users must upgrade to version 2.3.8 to remediate the vulnerabilities.
[WID-SEC-2026-2113] Froxlor: Mehrere Schwachstellen CVSS Base Score 9.9 (kritisch) CVSS Temporal Score 8.9 (hoch) Remoteangriff ja Datum 28.06.2026 Stand 29.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Produktbeschreibung Froxlor ist eine Web-basierte Server-Management-Software. Produkte 28.06.2026 Open Source Froxlor <2.3.8 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Froxlor ausnutzen, um Cross-Site-Scripting- oder SQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht. CVE Informationen Versionshistorie Feedback zum Advisory geben