Cross-site scripting in Froxlor - #VU152726

 

Cross-site scripting in Froxlor - #VU152726

Published: September 29, 2026


Vulnerability identifier: #VU152726
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in an administrator's authenticated session.

The vulnerability exists due to cross-site scripting in the customer theme field and customer overview listing when an administrator with the optional Theme column enabled views a customer-controlled theme value. A remote user can submit a theme-change request containing a crafted HTML and JavaScript payload to execute arbitrary JavaScript in an administrator's authenticated session.

User interaction is required because an administrator must view the customer overview with the optional Theme column enabled.


Affected software

Froxlor

Remediation

Install security update from vendor's website.

Froxlor - update to 2.3.14

External References

Related Security Bulletins