Medium severity6.1NVD Advisory· Published Apr 13, 2022· Updated Jun 17, 2026
CVE-2020-29653
CVE-2020-29653
Description
Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
froxlor/froxlorPackagist | <= 0.10.22 | — |
Affected products
3Patches
Vulnerability mechanics
References
7- github.com/Froxlor/Froxlor/commits/masternvdPatchThird Party Advisory
- nozero.io/en/cve-2020-29653-froxlor-html-injection-dangling-markup/nvdExploitThird Party Advisory
- github.com/Froxlor/Froxlor/security/advisoriesnvdNot ApplicableThird Party AdvisoryWEB
- github.com/advisories/GHSA-j739-gw6q-f4c7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-29653ghsaADVISORY
- github.com/Froxlor/Froxlor/commit/6bf5eccc2477257b6c1760a3c3784ae7e0554ce0ghsaWEB
- nozero.io/en/cve-2020-29653-froxlor-html-injection-dangling-markupghsaWEB
News mentions
0No linked articles in our index yet.