Vulnerabilities > Froxlor > Froxlor > 0.9.37

DATE CVE VULNERABILITY TITLE RISK
2020-03-09 CVE-2020-10236 Improper Input Validation vulnerability in Froxlor
An issue was discovered in Froxlor before 0.10.14.
local
low complexity
froxlor CWE-20
6.1
2020-03-09 CVE-2020-10235 Improper Encoding or Escaping of Output vulnerability in Froxlor
An issue was discovered in Froxlor before 0.10.14.
network
low complexity
froxlor CWE-116
8.8
2018-06-26 CVE-2018-1000527 Deserialization of Untrusted Data vulnerability in Froxlor
Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution.
network
low complexity
froxlor CWE-502
7.2
2018-06-22 CVE-2018-12642 Incorrect Permission Assignment for Critical Resource vulnerability in Froxlor
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
network
low complexity
froxlor CWE-732
7.5