Froxlor

Froxlor

76 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 26.09.2026 13:24:03
  • Zuletzt bearbeitet 26.09.2026 23:16:33

Froxlor through 2.3.10 does not filter sensitive columns from API responses: Domains::get(), Domains::listing(), SubDomains::get(), and the admin branch of SubDomains::listing() perform a wildcard SELECT over the panel_domains table and return the ro...

  • EPSS 0.29%
  • Veröffentlicht 26.09.2026 13:24:02
  • Zuletzt bearbeitet 26.09.2026 23:16:32

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. B...

  • EPSS 0.13%
  • Veröffentlicht 26.09.2026 13:24:02
  • Zuletzt bearbeitet 28.09.2026 15:17:11

Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_...

  • EPSS 0.26%
  • Veröffentlicht 14.09.2026 12:48:31
  • Zuletzt bearbeitet 23.09.2026 17:17:47

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that ar...

  • EPSS 0.23%
  • Veröffentlicht 14.09.2026 12:48:30
  • Zuletzt bearbeitet 08.10.2026 16:17:59

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary send...

  • EPSS 0.21%
  • Veröffentlicht 14.09.2026 12:48:30
  • Zuletzt bearbeitet 08.10.2026 16:17:59

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden server...

  • EPSS 0.1%
  • Veröffentlicht 14.09.2026 12:48:23
  • Zuletzt bearbeitet 08.10.2026 16:16:50

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems whe...

  • EPSS 0.25%
  • Veröffentlicht 13.09.2026 10:45:37
  • Zuletzt bearbeitet 23.09.2026 17:17:44

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives...

  • EPSS 0.23%
  • Veröffentlicht 18.08.2026 20:18:01
  • Zuletzt bearbeitet 08.09.2026 21:02:26

Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a valid session ...

  • EPSS 0.38%
  • Veröffentlicht 18.08.2026 20:16:36
  • Zuletzt bearbeitet 08.09.2026 21:02:26

Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::w...