CVE-2020-10235: OS Command Injection
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of backupExistingDatabase in install/lib/class.FroxlorInstall.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-10235?
CVE-2020-10235 is a vulnerability in Froxlor before version 0.10.14 that allows remote attackers to execute arbitrary code via the database configuration options.
How severe is CVE-2020-10235?
CVE-2020-10235 has a severity score of 8.8 (high).
Which software versions are affected by CVE-2020-10235?
Froxlor versions up to and excluding 0.10.14 are affected by CVE-2020-10235.
How can I fix CVE-2020-10235?
To fix CVE-2020-10235, update Froxlor to version 0.10.14 or higher.
Is there any additional information available for CVE-2020-10235?
Yes, you can find more information about CVE-2020-10235 in the references provided: [Bugzilla](https://bugzilla.suse.com/show_bug.cgi?id=1165721), [GitHub Commit 1](https://github.com/Froxlor/Froxlor/commit/62ce21c9ec393f9962515c88f0c489ace42bf656), [GitHub Commit 2](https://github.com/Froxlor/Froxlor/commit/7e361274c5bf687b6a42dd1871f6d75506c5d207).