Improper Authorization Affecting froxlor/froxlor package, versions <2.0.0
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.05% (23rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-FROXLORFROXLOR-3186306
- published 1 Jan 2023
- disclosed 1 Jan 2023
- credit leorac
Introduced: 1 Jan 2023
CVE-2022-4868 Open this link in a new tabHow to fix?
Upgrade froxlor/froxlor
to version 2.0.0 or higher.
Overview
froxlor/froxlor is a server administration software.
Affected versions of this package are vulnerable to Improper Authorization by allowing reseller users to view DB servers and cronjobs to which they don't have access.
References
CVSS Scores
version 3.1