CVE-2026-41237
- EPSS 0.27%
- Veröffentlicht 04.06.2026 17:55:19
- Zuletzt bearbeitet 05.06.2026 20:17:31
Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all val...
CVE-2026-41236
- EPSS 0.37%
- Veröffentlicht 04.06.2026 17:52:10
- Zuletzt bearbeitet 08.06.2026 16:16:38
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` u...
CVE-2026-41235
- EPSS 0.23%
- Veröffentlicht 04.06.2026 17:50:09
- Zuletzt bearbeitet 08.06.2026 19:16:44
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enfor...
CVE-2026-41234
- EPSS 0.27%
- Veröffentlicht 04.06.2026 17:47:12
- Zuletzt bearbeitet 05.06.2026 15:09:21
Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into ...
CVE-2026-41233
- EPSS 0.26%
- Veröffentlicht 23.04.2026 04:00:19
- Zuletzt bearbeitet 27.04.2026 16:59:16
Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permiss...
- EPSS 0.23%
- Veröffentlicht 23.04.2026 03:54:55
- Zuletzt bearbeitet 27.04.2026 17:02:02
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part ...
CVE-2026-41231
- EPSS 0.41%
- Veröffentlicht 23.04.2026 03:52:42
- Zuletzt bearbeitet 27.04.2026 17:01:42
Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` parameter to `FileDir::makeCorrectDir()`, bypassing t...
CVE-2026-41230
- EPSS 0.35%
- Veröffentlicht 23.04.2026 03:47:11
- Zuletzt bearbeitet 27.04.2026 17:01:11
Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by...
CVE-2026-41229
- EPSS 0.48%
- Veröffentlicht 23.04.2026 03:44:25
- Zuletzt bearbeitet 27.04.2026 17:00:51
Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` pe...
CVE-2026-41228
- EPSS 0.52%
- Veröffentlicht 23.04.2026 03:41:47
- Zuletzt bearbeitet 27.04.2026 17:00:33
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authentic...