CVE-2022-3721: Code Injection in froxlor/froxlor
Published Nov 4, 2022
·Updated
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
Other sources
Froxlor prior to version 0.10.39 is vulnerable to Code Injection.
— GitHub
Affected Software
2 affected componentsFixes available
Froxlor Froxlor<0.10.39
composer/froxlor/froxlor<0.10.39
0.10.39
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/froxlor/froxlorto a version that resolves this vulnerability.Fixed in 0.10.39 - Upgrade
Upgrade
froxlor/froxlorto a version that resolves this vulnerability.Fixed in 0.10.39
Event History
Nov 4, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·07:01 PM
Nov 29, 58461
Event
08:46 AM
Frequently Asked Questions
1
What is CVE-2022-3721?
CVE-2022-3721 is a code injection vulnerability in the GitHub repository froxlor/froxlor prior to version 0.10.39.
2
How severe is CVE-2022-3721?
CVE-2022-3721 has a severity rating of high with a CVSS score of 4.6.
3
How does CVE-2022-3721 affect Froxlor?
CVE-2022-3721 affects Froxlor versions prior to 0.10.39.
4
How can I fix CVE-2022-3721?
To fix CVE-2022-3721, update Froxlor to version 0.10.39 or later.
5
What is the CWE ID for CVE-2022-3721?
The CWE ID for CVE-2022-3721 is CWE-94 and CWE-79.