CVE-2020-36978
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
27/01/2026
Last modified:
27/01/2026
Description
Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
6.40
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://froxlor.org/
- https://froxlor.org/download/
- https://www.exploit-db.com/exploits/49063
- https://www.vulncheck.com/advisories/froxlor-froxlor-server-management-panel-persistent-cross-site-scripting
- https://www.vulnerability-lab.com/get_content.php?id=2241
- https://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M.
- https://www.vulnerability-lab.com/show.php?user=Vulnerability-Lab



