Vulnerability record · CVE-2023-2034 · published 14 April 2023
CVE-2023-2034: Froxlor unrestricted file upload with dangerous file type
Froxlor · Froxlor
Froxlor before 2.0.14 allows an authenticated user to upload files of a dangerous type without restriction (CWE-434). Because the upload is unrestricted, a malicious file can be placed on the server and potentially executed, undermining the hosting panel's integrity.
Description
Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with a very high EPSS score and public exploit detail make this a serious risk for exposed Froxlor instances, though it requires an authenticated account and is not in KEV.
What it is
Froxlor before 2.0.14 allows an authenticated user to upload files of a dangerous type without restriction (CWE-434). Because the upload is unrestricted, a malicious file can be placed on the server and potentially executed, undermining the hosting panel's integrity.
Impact
An attacker with a low-privileged account can upload a dangerous file and, if it is reachable and executable, run code in the context of the web server, gaining high confidentiality, integrity and availability impact.
Attack surface
Reached over the network through the Froxlor web interface; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). No authentication bypass is needed, but a valid account is required.
Exploitation
EPSS is very high (0.7143, 99.4th percentile) and the huntr reference is tagged Exploit, indicating public exploit detail exists; the CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded.
What to do
- Upgrade Froxlor to 2.0.14 or later, applying the referenced patch commit.
- Restrict upload functionality to trusted roles and validate file type, extension and content on the server side.
- Store uploaded files outside the web root and disable execution in upload directories.
- Monitor and alert on uploads of executable or script file types.
- Review accounts with upload permissions and remove unused ones.
Detection
- Audit Froxlor upload logs for files with executable or script extensions.
- Alert on new files written to web-accessible upload directories.
- Monitor web server logs for requests to uploaded files that result in code execution.
- Check for unexpected processes spawned by the web server user.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-2034 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-2034), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.