CVE-2024-34070
Blind XSS Leading to Froxlor Application Compromise
Summary
Remediation
Upgrade to the fixed version using your package manager.
composer require "froxlor/froxlor:^2.1.9"
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (1)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| froxlor/froxlor | packagist | 0.10.0, 0.10.0-rc1, 0.10.0-rc2, 0.10.1 (+83 more) | 2.1.9 |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-79Cross-site Scripting (XSS)MITRE
- CWE-80
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 9.6 score means for each attack dimension.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
References
Frequently Asked Questions
- What is CVE-2024-34070?
- Blind XSS Leading to Froxlor Application Compromise This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.6/10).
- How do I check if my project is affected by CVE-2024-34070?
- CVE-2024-34070 affects froxlor/froxlor. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2024-34070 and 200,000+ other known vulnerabilities.
Severity & Exploitability
Exploitation is straightforward and causes maximum impact. Patch immediately.
Also Known As
Related CVEs
- CVE-2026-26279CRITICAL
Froxlor has Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection
- CVE-2023-3173CRITICAL
Froxlor vulnerable to Improper Restriction of Excessive Authentication Attempts
- CVE-2026-41229CRITICAL
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)
- CVE-2023-1307CRITICAL
Froxlor is vulnerable to authentication bypass
- CVE-2026-41228CRITICAL
Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution
- CVE-2026-41235HIGH
Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement
- CVE-2026-41236HIGH
Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path
- CVE-2026-30932HIGH
Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies