Stored Blind Cross-Site Scripting (XSS) Vulnerability in Froxlor Application
CVE-2024-34070
What is CVE-2024-34070?
Froxlor, an open-source server administration software, has a vulnerability present in versions prior to 2.1.9 that permits Stored Blind Cross-Site Scripting (XSS) through the Failed Login Attempts Logging Feature. This flaw allows an unauthenticated user to inject malicious scripts via the loginname parameter during login attempts. Once an administrator reviews the login logs, the injected scripts execute, enabling attackers to manipulate the application without the administrator's knowledge. Such exploitation could allow an attacker to orchestrate actions, including the potential for creating another administrator account controlled by the attacker, thus compromising the integrity of the entire system. Mitigation has been implemented in version 2.1.9.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Froxlor < 2.1.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
