CVE-2025-48958 - CVE House
Back to Database
Status published Medium CVE-2025-48958

Froxlor has an HTML Injection Vulnerability

Vulnerability Description

Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks, credential theft, and reputational damage by redirecting users to malicious external websites. The vulnerability has a medium severity, as it can be exploited through user input without authentication. Version 2.2.6 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48958

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Froxlor
Vulnerable Versions:
< 2.2.6

Timeline

Official Publish: June 2nd, 2025
Last Modified: June 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Weaknesses (CWE)