High severity8.8NVD Advisory· Published Mar 9, 2020· Updated Jun 17, 2026
CVE-2020-10235
CVE-2020-10235
Description
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in install/lib/class.FroxlorInstall.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
froxlor/froxlorPackagist | < 0.10.14 | 0.10.14 |
Affected products
3- Froxlor/Froxlordescription
Patches
Vulnerability mechanics
References
6- github.com/Froxlor/Froxlor/commit/62ce21c9ec393f9962515c88f0c489ace42bf656nvdPatchWEB
- github.com/Froxlor/Froxlor/commit/7e361274c5bf687b6a42dd1871f6d75506c5d207nvdPatchWEB
- github.com/Froxlor/Froxlor/compare/0.10.13...0.10.14nvdPatchWEB
- bugzilla.suse.com/show_bug.cginvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-p29c-jpgj-v57rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-10235ghsaADVISORY
News mentions
0No linked articles in our index yet.