# Description 1. CVE-2023-0565 - Language Dropdown Menu Manipulation 1. Discoverer: Ahmed Hassan 1. Vendor of Product: FroxLor 1. Affected Product: Release 2.0 # POC 1. Login 2. Go Miscellaneous -> Email & file templates 3. Add Template -> Change & Save and intercept the Request 4. Change the Language to anything you want 5. As you can see there are specific Languages nobody can select anything else. 6. Lets put HACKED inside it :) 7. The language is now HACKED lets see 8. as you can see the language is now HACKED and it got accepted even if we have a Dropdown Menu with specific Languages to choose from PoC Link: [[https://mega.nz/file/vBl2EJoT#KVnXKVqLOl5Qhux9lJrcr53egaZtEzu00UR0VEqOynE](https://mega.nz/file/jU8zGYJZ#0JCh4kId2xAhbBy8H4mCsp6VE7J0JlES8kewOJjiWT8)https://mega.nz/file/jU8zGYJZ#0JCh4kId2xAhbBy8H4mCsp6VE7J0JlES8kewOJjiWT8](https://mega.nz/file/nZUXHLKQ#aeh01wujUHXw9DkXBU6ESSpx77Hh_uQHDUevg7jYWwo) ![Language Dropdown Menu Manipulation](https://github.com/ahmedvienna/Vulnerabilities/assets/80028768/30045dd5-d6f4-49d9-a796-44402344cad1)