Arbitrary Code Execution via Unescaped Database Configuration Options in Froxlor

Arbitrary Code Execution via Unescaped Database Configuration Options in Froxlor

CVE-2020-10235 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in install/lib/class.FroxlorInstall.php.

Learn more about our Web Application Penetration Testing UK.