Cross-site scripting in Froxlor - #VU152726
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in an administrator's authenticated session.
The vulnerability exists due to cross-site scripting in the customer theme field and customer overview listing when an administrator with the optional Theme column enabled views a customer-controlled theme value. A remote user can submit a theme-change request containing a crafted HTML and JavaScript payload to execute arbitrary JavaScript in an administrator's authenticated session.
User interaction is required because an administrator must view the customer overview with the optional Theme column enabled.