Skip to content
Noroxi

froxlor records

48 published records for vendor froxlor.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 2.1%
Pre-auth RCE
1
With a fix record
91.7%
Median publish → KEV
No record has entered KEV

All records

48 records
  • CVE-2023-0315
    64This week

    Command Injection in froxlor/froxlor

    HighCVSS 8.8WeaponizedEPSS 98%

    froxlor · froxlorJan 15, 2023

  • Unrestricted Upload of File with Dangerous Type in froxlor/froxlor

    HighCVSS 8.8No exploitEPSS 71%

    froxlor · froxlorApr 13, 2023

  • Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

    CriticalCVSS 9.8Proof of conceptEPSS 12%

    froxlor · froxlorOct 12, 2021

  • Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/s

    CriticalCVSS 9.8No exploitEPSS 3%

    froxlor · froxlorSep 6, 2017

  • Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passw

    CriticalCVSS 9.8No exploitEPSS 2%

    froxlor · froxlorFeb 13, 2017

  • CVE-2023-3173
    39Monitor

    Improper Restriction of Excessive Authentication Attempts in froxlor/froxlor

    CriticalCVSS 9.8No exploitEPSS 1%

    froxlor · froxlorJun 8, 2023

  • CVE-2023-1307
    39Monitor

    Authentication Bypass by Primary Weakness in froxlor/froxlor

    CriticalCVSS 9.8No exploitEPSS 1%

    froxlor · froxlorMar 9, 2023

  • Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution

    CriticalCVSS 9.9No exploitEPSS 1%

    froxlor · froxlorApr 23, 2026

  • Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise

    CriticalCVSS 9.6Proof of conceptEPSS 1%

    froxlor · froxlorMay 14, 2024

  • CVE-2023-0877
    36Monitor

    Code Injection in froxlor/froxlor

    HighCVSS 8.8No exploitEPSS 4%

    froxlor · froxlorFeb 16, 2023

  • An issue was discovered in Froxlor before 0.10.14.

    HighCVSS 8.8No exploitEPSS 2%

    froxlor · froxlorMar 9, 2020

  • Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection

    CriticalCVSS 9.1No exploitEPSS 1%

    froxlor · froxlorMar 3, 2026

  • Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)

    CriticalCVSS 9.1No exploitEPSS 1%

    froxlor · froxlorApr 23, 2026

  • CVE-2023-0671
    35Monitor

    Code Injection in froxlor/froxlor

    HighCVSS 8.8No exploitEPSS 1%

    froxlor · froxlorFeb 3, 2023

  • CVE-2023-6069
    35Monitor

    Improper Link Resolution Before File Access in froxlor/froxlor

    HighCVSS 8.8No exploitEPSS 1%

    froxlor · froxlorNov 9, 2023

  • CVE-2023-1033
    35Monitor

    Cross-Site Request Forgery (CSRF) in froxlor/froxlor

    HighCVSS 8.8No exploitEPSS 0%

    froxlor · froxlorFeb 24, 2023

  • Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API

    HighCVSS 8.6No exploitEPSS 1%

    froxlor · froxlorMar 24, 2026

  • Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()

    HighCVSS 8.5No exploitEPSS 1%

    froxlor · froxlorApr 23, 2026

  • Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover

    HighCVSS 7.8No exploitEPSS 0%

    froxlor · froxlorMar 13, 2025

  • Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.

    HighCVSS 7.5No exploitEPSS 1%

    froxlor · froxlorJun 22, 2018

  • Froxlor username/surname AND company field Bypass

    HighCVSS 7.5No exploitEPSS 1%

    froxlor · froxlorJan 3, 2024

  • CVE-2023-2666
    30Monitor

    Allocation of Resources Without Limits or Throttling in froxlor/froxlor

    HighCVSS 7.5No exploitEPSS 1%

    froxlor · froxlorMay 11, 2023

  • Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron

    HighCVSS 7.5No exploitEPSS 1%

    froxlor · froxlorApr 23, 2026

  • CVE-2023-0564
    30Monitor

    Weak Password Requirements in froxlor/froxlor

    HighCVSS 7.5No exploitEPSS 0%

    froxlor · froxlorJan 28, 2023

  • Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclo

    HighCVSS 7.2No exploitEPSS 3%

    froxlor · froxlorJun 26, 2018