CVE-2020-29653: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.
References
Detect and mitigate CVE-2020-29653 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →