Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
{
"cpe": "cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.10.30"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}