Vulnerabilities > Froxlor > Froxlor > 0.9.39.2

DATE CVE VULNERABILITY TITLE RISK
2020-03-09 CVE-2020-10235 Improper Input Validation vulnerability in Froxlor
An issue was discovered in Froxlor before 0.10.14.
network
low complexity
froxlor CWE-20
6.5
2018-06-26 CVE-2018-1000527 Deserialization of Untrusted Data vulnerability in Froxlor
Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution.
network
low complexity
froxlor CWE-502
6.5
2018-06-22 CVE-2018-12642 Incorrect Permission Assignment for Critical Resource vulnerability in Froxlor
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
network
low complexity
froxlor CWE-732
5.0