vendor:
Froxlor
by:
Martin Cernac
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Froxlor
Affected Version From: 2000.10.28
Affected Version To: 0.10.29.1
Patch Exists: YES
Related CWE: 2021-42325
CPE: a:froxlor:froxlor
Platforms Tested: Ubuntu
2021
Froxlor 0.10.29.1 – SQL Injection (Authenticated)
Froxlor 0.10.28 and 0.10.29.x are affected by an SQL Injection from the authenticated customer panel. This allows an attacker to escalate privilege by creating a Froxlor administrator account and use it to get Remote Code Execution as root on the target machine.
Mitigation:
Ensure that the 'User/Database name' field is not enabled for customers.