CVE-2026-54348
- EPSS 0.61%
- Veröffentlicht 18.08.2026 20:15:31
- Zuletzt bearbeitet 08.09.2026 21:02:26
Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enf...
CVE-2026-54543
- EPSS 0.43%
- Veröffentlicht 18.08.2026 20:12:12
- Zuletzt bearbeitet 08.09.2026 21:02:26
Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab characters, semic...
- EPSS 0.59%
- Veröffentlicht 18.08.2026 20:10:37
- Zuletzt bearbeitet 08.09.2026 21:02:26
Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Comman...
CVE-2026-52793
- EPSS 0.3%
- Veröffentlicht 18.08.2026 20:09:33
- Zuletzt bearbeitet 08.09.2026 21:02:26
Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an administrator or customer account without checking ...
CVE-2026-41237
- EPSS 0.27%
- Veröffentlicht 04.06.2026 17:55:19
- Zuletzt bearbeitet 22.07.2026 20:10:00
Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all val...
CVE-2026-41236
- EPSS 0.37%
- Veröffentlicht 04.06.2026 17:52:10
- Zuletzt bearbeitet 22.07.2026 20:10:00
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` u...
CVE-2026-41235
- EPSS 0.23%
- Veröffentlicht 04.06.2026 17:50:09
- Zuletzt bearbeitet 22.07.2026 20:10:00
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enfor...
CVE-2026-41234
- EPSS 0.27%
- Veröffentlicht 04.06.2026 17:47:12
- Zuletzt bearbeitet 22.07.2026 20:10:00
Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into ...
CVE-2026-41233
- EPSS 0.26%
- Veröffentlicht 23.04.2026 04:00:19
- Zuletzt bearbeitet 27.04.2026 16:59:16
Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permiss...
- EPSS 0.23%
- Veröffentlicht 23.04.2026 03:54:55
- Zuletzt bearbeitet 27.04.2026 17:02:02
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part ...