CVE-2026-100720
- EPSS 0.22%
- Veröffentlicht 26.09.2026 13:24:10
- Zuletzt bearbeitet 26.09.2026 23:16:33
Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with o...
CVE-2026-100719
- EPSS 0.24%
- Veröffentlicht 26.09.2026 13:24:09
- Zuletzt bearbeitet 26.09.2026 23:16:33
Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcrypt password hashes for protected-directory users, e...
CVE-2026-100718
- EPSS 0.19%
- Veröffentlicht 26.09.2026 13:24:09
- Zuletzt bearbeitet 26.09.2026 23:16:33
Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external allowed-sender domains (mail.enable_allow_sender = 1...
CVE-2026-100717
- EPSS 0.3%
- Veröffentlicht 26.09.2026 13:24:08
- Zuletzt bearbeitet 30.09.2026 18:18:02
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (u...
CVE-2026-100716
- EPSS 0.39%
- Veröffentlicht 26.09.2026 13:24:07
- Zuletzt bearbeitet 28.09.2026 15:17:11
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in i...
CVE-2026-100715
- EPSS 0.4%
- Veröffentlicht 26.09.2026 13:24:07
- Zuletzt bearbeitet 28.09.2026 17:17:45
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir a...
CVE-2026-100714
- EPSS 0.55%
- Veröffentlicht 26.09.2026 13:24:06
- Zuletzt bearbeitet 26.09.2026 23:16:33
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme....
CVE-2026-100712
- EPSS 0.13%
- Veröffentlicht 26.09.2026 13:24:05
- Zuletzt bearbeitet 28.09.2026 15:17:11
froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET request to the 2FA management page (e.g. /customer_index.php?page=2fa&action=delete), with no confirmation, re-authentication, or C...
CVE-2026-100713
- EPSS 0.16%
- Veröffentlicht 26.09.2026 13:24:05
- Zuletzt bearbeitet 26.09.2026 23:16:33
Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCor...
CVE-2026-100711
- EPSS 0.26%
- Veröffentlicht 26.09.2026 13:24:04
- Zuletzt bearbeitet 28.09.2026 17:17:45
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after pass...