SCA: security update for froxlor/froxlor (GHSA-7j6w-p859-464f)

high Tenable Cloud Security Plugin ID 421095

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows
users (such as resellers or customers) to create accounts with the same email address as an existing
account. This creates potential issues with account identification and security. This vulnerability can be
exploited by authenticated users (e.g., reseller, customer) who can create accounts with the same email
address that has already been used by another account, such as the admin. The attack vector is email-
based, as the system does not prevent multiple accounts from registering the same email address, leading
to possible conflicts and security issues. Version 2.2.6 fixes the issue. (CVE-2025-29773)

See Also

https://github.com/advisories/GHSA-7j6w-p859-464f

Plugin Details

Severity: High

ID: 421095

Version: Revision 1.11

Type: Local

Family: SCA Checks

Published: 3/12/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-29773

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/11/2025

Vulnerability Publication Date: 3/11/2025

Reference Information

CVE: CVE-2025-29773

cwe: CWE-287