Vulnerabilities > Froxlor > High

DATE CVE VULNERABILITY TITLE RISK
2023-01-16 CVE-2023-0315 Unspecified vulnerability in Froxlor
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
network
low complexity
froxlor
8.8
2020-03-09 CVE-2020-10235 Improper Encoding or Escaping of Output vulnerability in Froxlor
An issue was discovered in Froxlor before 0.10.14.
network
low complexity
froxlor CWE-116
8.8
2018-06-26 CVE-2018-1000527 Deserialization of Untrusted Data vulnerability in Froxlor
Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution.
network
low complexity
froxlor CWE-502
7.2
2018-06-22 CVE-2018-12642 Incorrect Permission Assignment for Critical Resource vulnerability in Froxlor
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
network
low complexity
froxlor CWE-732
7.5