
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical Stored Blind Cross-Site Scripting (XSS) vulnerability (CVE-2024-34070) was identified in the Failed Login Attempts Logging Feature of Froxlor, an open-source server administration software. The vulnerability affects versions prior to 2.1.9 and has been assigned a CVSS score of 9.6. An unauthenticated user can inject malicious scripts through the loginname parameter during login attempts, which are then executed when viewed by administrators in the System Logs (GitHub Advisory, NVD).
The vulnerability exploits the application's XSS sanitization library, which was bypassed using data binding and interpolation features of Vue.js. The vulnerability occurs when user inputs are not properly sanitized and are stored on the server. The attack vector is through the loginname parameter during login attempts, where malicious scripts can be injected. The CVSS v3.1 base score is 9.6 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H (Security Online, GitHub Advisory).
The vulnerability's impact is severe, allowing attackers to perform various malicious actions without administrator knowledge. Successful exploitation can lead to complete system compromise, including the ability to add unauthorized administrator accounts, steal sensitive user data, modify website content, disrupt services, and plant malware. Additionally, attackers can potentially access user credentials, session tokens, and personally identifiable information (Security Online).
The vulnerability is exploitable by unauthenticated remote attackers. A working exploit has been demonstrated that forces an administrator to add a new malicious attacker-controlled Administrator User. The attack requires no special privileges and can be executed through the login attempt mechanism (GitHub Advisory).
The vulnerability has been patched in Froxlor version 2.1.9. Server administrators using Froxlor are strongly urged to update immediately to the patched version. Additional security measures recommended include enabling two-factor authentication (2FA) for Froxlor administrators and implementing web application firewalls (WAFs). The fix includes proper input validation and sanitization mechanisms on all user inputs, particularly sanitizing {{ and }} to prevent data binding and interpolation of Vue.js (Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."