CVE-2015-5959: Froxlor

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.

Affected products

  • Froxlor Froxlor: up to and including 0.9.33.1

Published 2017-09-06. Last modified 2026-06-17.