以下是关于漏洞的关键信息: Vulnerability Summary Title: Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting Severity: Medium Date: January 27, 2026 Vulnerability Details Product: Froxlor Server Management Panel 0.10.16 CVE ID: CVE-2020-36978 CWE ID: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVSS V4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N Description: Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules. References ExploitDB-49063 Official Froxlor Homepage Froxlor Download Page Vulnerability Lab Advisory Vulnerability Lab Profile Researcher Profile Credit Researcher: Vulnerability-Lab