CVE-2020-10236: Improper Input Validation
An issue was discovered in Froxlor. It created files with static names in /tmp
during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, the flaw exists in _createUserdataConf
of the install/lib/class.FroxlorInstall.php
file.
References
Detect and mitigate CVE-2020-10236 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →