CVE-2020-10236: Input Validation
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, because of createUserdataConf in install/lib/class.FroxlorInstall.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-10236?
CVE-2020-10236 is a vulnerability in Froxlor before version 0.10.14 that allows local attackers to cause denial of service (DoS) or disclose information from config files.
What is the severity of CVE-2020-10236?
CVE-2020-10236 has a severity rating of 6.1 (medium).
How does CVE-2020-10236 allow attackers to cause DoS or disclose information?
CVE-2020-10236 allows local attackers to cause DoS or disclose information by creating files with static names in /tmp during installation if the installation directory is not writable.
Which software versions are affected by CVE-2020-10236?
Froxlor versions up to but excluding 0.10.14 are affected by CVE-2020-10236.
How can I fix CVE-2020-10236?
To fix CVE-2020-10236, it is recommended to upgrade Froxlor to version 0.10.14 or later.