CVE-2023-3668: Improper Encoding or Escaping of Output in froxlor/froxlor
Published Jul 14, 2023
·Updated
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
Affected Software
2 affected componentsFixes available
composer/froxlor/froxlor<2.0.21
2.0.21
Froxlor Froxlor<2.0.21
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/froxlor/froxlorto a version that resolves this vulnerability.Fixed in 2.0.21
Event History
Jul 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
01:15 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
03:32 AM
Jan 14, 58462
Event
12:56 PM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-3668.
2
What is the severity of CVE-2023-3668?
The severity of CVE-2023-3668 is critical, with a severity value of 7.2.
3
What software is affected by CVE-2023-3668?
The affected software is Froxlor Froxlor prior to version 2.0.21.
4
How can I fix CVE-2023-3668?
To fix CVE-2023-3668, update Froxlor Froxlor to version 2.0.21 or later.
5
Where can I find more information about CVE-2023-3668?
You can find more information about CVE-2023-3668 at the following references: [Huntr.dev](https://huntr.dev/bounties/df8cccf4-a340-440e-a7e0-1b42e757d66e), [GitHub Commit](https://github.com/froxlor/froxlor/commit/03b5a921ff308eeab21bf9d240f27783c8591965).