Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks, credential theft, and reputational damage by redirecting users to malicious external websites. The vulnerability has a medium severity, as it can be exploited through user input without authentication. Version 2.2.6 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Jun 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Froxlor
Froxlor froxlor |
|
CPEs | cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:* | |
Vendors & Products |
Froxlor
Froxlor froxlor |
Mon, 02 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 02 Jun 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks, credential theft, and reputational damage by redirecting users to malicious external websites. The vulnerability has a medium severity, as it can be exploited through user input without authentication. Version 2.2.6 fixes the issue. | |
Title | Froxlor has an HTML Injection Vulnerability | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-02T11:18:27.230Z
Updated: 2025-06-02T16:41:18.444Z
Reserved: 2025-05-28T18:49:07.585Z
Link: CVE-2025-48958

Updated: 2025-06-02T16:41:07.372Z

Status : Analyzed
Published: 2025-06-02T12:15:25.840
Modified: 2025-06-25T17:36:43.537
Link: CVE-2025-48958

No data.