{"id":"CVE-2022-3017","aliases":["GHSA-9xgp-3mxp-rv7x"],"url":"https://o3.security/vulnerability/CVE-2022-3017","summary":"Cross-Site Request Forgery (CSRF) in froxlor/froxlor","details":"Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.","published":"2022-08-28T13:50:08Z","modified":"2026-08-12T03:51:16.192438504Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"},"epss":{"score":0.00427,"percentile":0.36314,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"froxlor/froxlor","fixedVersion":"0.10.38"}],"fix":{"url":"https://github.com/froxlor/froxlor/commit/bbe82286aae21328668f24857995a67598fe978a","label":"froxlor/froxlor@bbe8228"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/5250c4b1-132b-4da6-9bd6-db36cb56bea0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3017.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3017"},{"type":"FIX","url":"https://github.com/froxlor/froxlor/commit/bbe82286aae21328668f24857995a67598fe978a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.192438504Z"}}