Medium severity6.1NVD Advisory· Published Mar 9, 2020· Updated Jun 17, 2026
CVE-2020-10236
CVE-2020-10236
Description
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, because of _createUserdataConf in install/lib/class.FroxlorInstall.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
froxlor/froxlorPackagist | < 0.10.14 | 0.10.14 |
Affected products
3- Froxlor/Froxlordescription
Patches
Vulnerability mechanics
References
5- github.com/Froxlor/Froxlor/commit/6b09720ef8a1cc008751dd0ca0140a0597fedce5nvdPatchWEB
- github.com/Froxlor/Froxlor/compare/0.10.13...0.10.14nvdPatchWEB
- bugzilla.suse.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-hvgf-2rf7-wrx9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-10236ghsaADVISORY
News mentions
0No linked articles in our index yet.