MEDIUM
Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter
Published Apr 13, 2022
6.1
MEDIUMCVSS 3.1
EPSS 1.43%
Description
Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1772 Advisory
- https://github.com/Froxlor/Froxlor/commit/6bf5eccc2477257b6c1760a3c3784ae7e0554ce0
- https://github.com/Froxlor/Froxlor/commits/master x_refsource_MISCPatchThird Party Advisory
- https://github.com/Froxlor/Froxlor/security/advisories x_refsource_MISCNot ApplicableThird Party Advisory
- https://github.com/advisories/GHSA-j739-gw6q-f4c7 Advisory
- https://nozero.io/en/cve-2020-29653-froxlor-html-injection-dangling-markup/ x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-29653
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1772 | Advisory | |
| https://github.com/Froxlor/Froxlor/commit/6bf5eccc2477257b6c1760a3c3784ae7e0554ce0 | ||
| https://github.com/Froxlor/Froxlor/commits/master | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/Froxlor/Froxlor/security/advisories | x_refsource_MISCNot ApplicableThird Party Advisory | |
| https://github.com/advisories/GHSA-j739-gw6q-f4c7 | Advisory | |
| https://nozero.io/en/cve-2020-29653-froxlor-html-injection-dangling-markup/ | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-29653 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 13, 2022
Updated Aug 4, 2024
Reserved Dec 9, 2020
Link CVE-2020-29653
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-1772 GHSA-J739-GW6Q-F4C7 Assigner mitre
Published Apr 13, 2022
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2022-1772