U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-29773

Change History

New CVE Received from GitHub, Inc. 3/13/2025 1:15:37 PM

Action Type Old Value New Value
Added Description

								
							
							
						
Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the same email address as an existing account. This creates potential issues with account identification and security. This vulnerability can be exploited by authenticated users (e.g., reseller, customer) who can create accounts with the same email address that has already been used by another account, such as the admin. The attack vector is email-based, as the system does not prevent multiple accounts from registering the same email address, leading to possible conflicts and security issues. Version 2.2.6 fixes the issue.
Added CVSS V3.1

								
							
							
						
AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Added CWE

								
							
							
						
CWE-287
Added Reference

								
							
							
						
https://github.com/froxlor/Froxlor/commit/a43d53d54034805e3e404702a01312fa0c40b623
Added Reference

								
							
							
						
https://github.com/froxlor/Froxlor/security/advisories/GHSA-7j6w-p859-464f
Added Reference

								
							
							
						
https://mega.nz/file/h8oFHQrL#I4V02_BWee4CCx7OoBl_2Ufkd5Wc7fvs5aCatGApkoQ