Bugzilla – Bug 1216204
VUL-0: CVE-2023-5564: froxlor: HTML injection Leads to Open redirection
Last modified: 2023-12-08 12:52:58 UTC
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5564 https://huntr.dev/bounties/9254d8f3-a847-4ae8-8477-d2ce027cff5c/ https://github.com/froxlor/froxlor/commit/e8ed43056c1665522a586e3485da67f2bdf073aa
might be relevant for Backports, the version is quite old though. Not easy to very. Maybe worth to drop froxlor from Backports for 15.6 as there are quite a few CVEs and no active maintainer anymore ?
it has been deleted in openSUSE:Backports:SLE-15-SP6 via https://build.opensuse.org/request/show/1103489 , we should not ship it anymore in Leap 15.6.