Froxlor

Froxlor

58 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.26%
  • Veröffentlicht 23.04.2026 04:00:19
  • Zuletzt bearbeitet 27.04.2026 16:59:16

Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permiss...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.04.2026 03:54:55
  • Zuletzt bearbeitet 27.04.2026 17:02:02

Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part ...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 23.04.2026 03:52:42
  • Zuletzt bearbeitet 27.04.2026 17:01:42

Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` parameter to `FileDir::makeCorrectDir()`, bypassing t...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 23.04.2026 03:47:11
  • Zuletzt bearbeitet 27.04.2026 17:01:11

Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 23.04.2026 03:44:25
  • Zuletzt bearbeitet 27.04.2026 17:00:51

Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` pe...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 23.04.2026 03:41:47
  • Zuletzt bearbeitet 27.04.2026 17:00:33

Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authentic...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 24.03.2026 18:46:13
  • Zuletzt bearbeitet 26.03.2026 12:17:21

Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An att...

Exploit
  • EPSS 0.8%
  • Veröffentlicht 03.03.2026 22:31:58
  • Zuletzt bearbeitet 05.03.2026 21:19:02

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated ...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 02.06.2025 11:18:27
  • Zuletzt bearbeitet 25.06.2025 17:36:43

Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 13.03.2025 17:15:37
  • Zuletzt bearbeitet 03.04.2025 18:25:43

Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the same email address as an existing account. This creates potential issues with ...