← Vulnerability feed

Vulnerability record · CVE-2023-2034 · published 14 April 2023

CVE-2023-2034: Froxlor unrestricted file upload with dangerous file type

Froxlor · Froxlor

Froxlor before 2.0.14 allows an authenticated user to upload files of a dangerous type without restriction (CWE-434). Because the upload is unrestricted, a malicious file can be placed on the server and potentially executed, undermining the hosting panel's integrity.

8.8 CVSS 3.1 High EPSS 71% · top 0.6% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with a very high EPSS score and public exploit detail make this a serious risk for exposed Froxlor instances, though it requires an authenticated account and is not in KEV.

What it is

Froxlor before 2.0.14 allows an authenticated user to upload files of a dangerous type without restriction (CWE-434). Because the upload is unrestricted, a malicious file can be placed on the server and potentially executed, undermining the hosting panel's integrity.

Impact

An attacker with a low-privileged account can upload a dangerous file and, if it is reachable and executable, run code in the context of the web server, gaining high confidentiality, integrity and availability impact.

Attack surface

Reached over the network through the Froxlor web interface; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). No authentication bypass is needed, but a valid account is required.

Exploitation

EPSS is very high (0.7143, 99.4th percentile) and the huntr reference is tagged Exploit, indicating public exploit detail exists; the CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded.

What to do

  • Upgrade Froxlor to 2.0.14 or later, applying the referenced patch commit.
  • Restrict upload functionality to trusted roles and validate file type, extension and content on the server side.
  • Store uploaded files outside the web root and disable execution in upload directories.
  • Monitor and alert on uploads of executable or script file types.
  • Review accounts with upload permissions and remove unused ones.

Detection

  • Audit Froxlor upload logs for files with executable or script extensions.
  • Alert on new files written to web-accessible upload directories.
  • Monitor web server logs for requests to uploaded files that result in code execution.
  • Check for unexpected processes spawned by the web server user.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-2034 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-41228Froxlor php remote file inclusion vulnerabilityFroxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does…EPSS 0.75%9.8CVE-2023-3173Froxlor improper restriction of authentication attempts vulnerabilityImproper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.EPSS 1.1%9.8CVE-2023-1307Froxlor vulnerabilityAuthentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.EPSS 1.1%9.8CVE-2021-42325Froxlor sql injection vulnerabilityFroxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.EPSS 12%9.8CVE-2015-5959Froxlor information exposure vulnerabilityFroxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.…EPSS 3.1%9.8CVE-2016-5100Froxlor vulnerabilityFroxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset…EPSS 1.9%9.1CVE-2026-41229Froxlor code injection vulnerabilityFroxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quo…EPSS 0.69%9.1CVE-2026-26279Froxlor os command injection vulnerabilityFroxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disable…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2023-2034), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.