CVE-2020-10237: Froxlor
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at the right time, because of _createUserdataConf in install/lib/class.FroxlorInstall.php.
Affected products
- Froxlor Froxlor: up to and including 0.10.15
Published 2020-03-09. Last modified 2026-06-17.