Froxlor

Froxlor

76 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 26.09.2026 13:24:10
  • Zuletzt bearbeitet 26.09.2026 23:16:33

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with o...

  • EPSS 0.24%
  • Veröffentlicht 26.09.2026 13:24:09
  • Zuletzt bearbeitet 26.09.2026 23:16:33

Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcrypt password hashes for protected-directory users, e...

  • EPSS 0.19%
  • Veröffentlicht 26.09.2026 13:24:09
  • Zuletzt bearbeitet 26.09.2026 23:16:33

Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external allowed-sender domains (mail.enable_allow_sender = 1...

  • EPSS 0.3%
  • Veröffentlicht 26.09.2026 13:24:08
  • Zuletzt bearbeitet 30.09.2026 18:18:02

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (u...

  • EPSS 0.39%
  • Veröffentlicht 26.09.2026 13:24:07
  • Zuletzt bearbeitet 28.09.2026 15:17:11

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in i...

  • EPSS 0.4%
  • Veröffentlicht 26.09.2026 13:24:07
  • Zuletzt bearbeitet 28.09.2026 17:17:45

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir a...

  • EPSS 0.55%
  • Veröffentlicht 26.09.2026 13:24:06
  • Zuletzt bearbeitet 26.09.2026 23:16:33

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme....

  • EPSS 0.13%
  • Veröffentlicht 26.09.2026 13:24:05
  • Zuletzt bearbeitet 28.09.2026 15:17:11

froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET request to the 2FA management page (e.g. /customer_index.php?page=2fa&action=delete), with no confirmation, re-authentication, or C...

  • EPSS 0.16%
  • Veröffentlicht 26.09.2026 13:24:05
  • Zuletzt bearbeitet 26.09.2026 23:16:33

Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCor...

  • EPSS 0.26%
  • Veröffentlicht 26.09.2026 13:24:04
  • Zuletzt bearbeitet 28.09.2026 17:17:45

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after pass...