Stored Blind Cross-Site Scripting (XSS) Vulnerability in Froxlor Application
CVE-2024-34070

9.7CRITICAL

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
14 May 2024

What is CVE-2024-34070?

Froxlor, an open-source server administration software, has a vulnerability present in versions prior to 2.1.9 that permits Stored Blind Cross-Site Scripting (XSS) through the Failed Login Attempts Logging Feature. This flaw allows an unauthenticated user to inject malicious scripts via the loginname parameter during login attempts. Once an administrator reviews the login logs, the injected scripts execute, enabling attackers to manipulate the application without the administrator's knowledge. Such exploitation could allow an attacker to orchestrate actions, including the potential for creating another administrator account controlled by the attacker, thus compromising the integrity of the entire system. Mitigation has been implemented in version 2.1.9.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Froxlor < 2.1.9

References

CVSS V3.1

Score:
9.7
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.