Impact
The vulnerability is a failure to validate the mysql_server parameter in the Mysqls.add API. Attackers can supply a disallowed server index and create MySQL databases and users on servers that are not in the customer's allowed_mysqlserver list. This grants the attacker the ability to create resources on restricted servers, leading to unauthorized data access and potential service disruption.
Affected Systems
The flaw impacts installations of Froxlor before version 2.3.7. All customers using these versions are vulnerable and can exploit the issue if they can reach the Mysqls.add API.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No exploitation probability was reported and the vulnerability is not listed in the CISA KEV catalog. Attackers need the ability to call the Mysqls.add API, which may be accessible to authenticated users or exposed via some other vulnerability. Once accessed, the bug provides a privilege‑escalation path to create databases and users on unauthorized servers.
OpenCVE Enrichment