CVE-2026-55593
- EPSS 0.23%
- Veröffentlicht 18.08.2026 20:18:01
- Zuletzt bearbeitet 19.08.2026 19:17:20
Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a valid session ...
CVE-2026-54347
- EPSS 0.38%
- Veröffentlicht 18.08.2026 20:16:36
- Zuletzt bearbeitet 19.08.2026 19:17:19
Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::w...
CVE-2026-54348
- EPSS 0.61%
- Veröffentlicht 18.08.2026 20:15:31
- Zuletzt bearbeitet 19.08.2026 20:17:16
Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enf...
CVE-2026-54543
- EPSS 0.43%
- Veröffentlicht 18.08.2026 20:12:12
- Zuletzt bearbeitet 19.08.2026 13:17:46
Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab characters, semic...
- EPSS 0.59%
- Veröffentlicht 18.08.2026 20:10:37
- Zuletzt bearbeitet 18.08.2026 21:17:18
Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Comman...
CVE-2026-52793
- EPSS 0.3%
- Veröffentlicht 18.08.2026 20:09:33
- Zuletzt bearbeitet 19.08.2026 16:17:45
Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an administrator or customer account without checking ...
CVE-2026-41237
- EPSS 0.27%
- Veröffentlicht 04.06.2026 17:55:19
- Zuletzt bearbeitet 22.07.2026 20:10:00
Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all val...
CVE-2026-41236
- EPSS 0.37%
- Veröffentlicht 04.06.2026 17:52:10
- Zuletzt bearbeitet 22.07.2026 20:10:00
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` u...
CVE-2026-41235
- EPSS 0.23%
- Veröffentlicht 04.06.2026 17:50:09
- Zuletzt bearbeitet 22.07.2026 20:10:00
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enfor...
CVE-2026-41234
- EPSS 0.27%
- Veröffentlicht 04.06.2026 17:47:12
- Zuletzt bearbeitet 22.07.2026 20:10:00
Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into ...