Froxlor
by Froxlor
Source repositories
CVEs (63)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10235 | Hig | 0.50 | 8.8 | 0.02 | Mar 9, 2020 | An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in… | ||
| CVE-2026-41237 | Hig | 0.49 | — | 0.00 | Jun 4, 2026 | Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input… | ||
| CVE-2026-41235 | Hig | 0.49 | — | 0.00 | Jun 4, 2026 | Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enforce that whitelist when… | ||
| CVE-2026-41230 | Hig | 0.48 | 8.5 | 0.00 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by the if/elseif validation… | ||
| CVE-2026-52793 | Hig | 0.46 | 8.1 | 0.00 | Aug 18, 2026 | Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an administrator or customer account without checking type_2fa, validating a TOTP… | ||
| CVE-2026-41234 | Hig | 0.42 | 7.6 | 0.00 | Jun 4, 2026 | Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which… | ||
| CVE-2026-41231 | Hig | 0.42 | 7.5 | 0.00 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` parameter to `FileDir::makeCorrectDir()`, bypassing the symlink validation that… | ||
| CVE-2023-50256 | Hig | 0.42 | 7.5 | 0.01 | Jan 3, 2024 | Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory… | ||
| CVE-2023-2666 | Hig | 0.42 | 7.5 | 0.01 | May 12, 2023 | Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16. | ||
| CVE-2018-12642 | Hig | 0.42 | 7.5 | 0.01 | Jun 22, 2018 | Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user. | ||
| CVE-2024-58383 | Hig | 0.40 | 7.3 | 0.00 | Sep 14, 2026 | Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are… | ||
| CVE-2026-54348 | Hig | 0.40 | 7.2 | 0.01 | Aug 18, 2026 | Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enforcing numeric element types.… | ||
| CVE-2023-3668 | Hig | 0.40 | 7.2 | 0.01 | Jul 14, 2023 | Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21. | ||
| CVE-2023-3172 | Hig | 0.40 | 7.2 | 0.01 | Jun 9, 2023 | Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20. | ||
| CVE-2018-1000527 | Hig | 0.40 | 7.2 | 0.02 | Jun 26, 2018 | Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution. This attack appear to be exploitable via Passing malicious PHP objection in $_POST['ssl_ipandport']. This… | ||
| CVE-2020-10237 | Med | 0.36 | 5.5 | 0.00 | Mar 9, 2020 | An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at… | ||
| CVE-2026-90767 | Med | 0.35 | 6.5 | 0.00 | Sep 13, 2026 | Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent… | ||
| CVE-2026-55593 | Med | 0.35 | 6.5 | 0.00 | Aug 18, 2026 | Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a valid session before routing state-changing… | ||
| CVE-2022-3017 | Med | 0.35 | 6.5 | 0.00 | Aug 28, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38. | ||
| CVE-2020-28957 | Med | 0.35 | 5.4 | 0.01 | Oct 22, 2021 | Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the name, firstname, or username input fields. |
- risk 0.50cvss 8.8epss 0.02
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in…
- risk 0.49cvss —epss 0.00
Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input…
- risk 0.49cvss —epss 0.00
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enforce that whitelist when…
- risk 0.48cvss 8.5epss 0.00
Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by the if/elseif validation…
- risk 0.46cvss 8.1epss 0.00
Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an administrator or customer account without checking type_2fa, validating a TOTP…
- risk 0.42cvss 7.6epss 0.00
Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which…
- risk 0.42cvss 7.5epss 0.00
Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` parameter to `FileDir::makeCorrectDir()`, bypassing the symlink validation that…
- risk 0.42cvss 7.5epss 0.01
Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory…
- risk 0.42cvss 7.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.
- risk 0.42cvss 7.5epss 0.01
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
- risk 0.40cvss 7.3epss 0.00
Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are…
- risk 0.40cvss 7.2epss 0.01
Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enforcing numeric element types.…
- risk 0.40cvss 7.2epss 0.01
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
- risk 0.40cvss 7.2epss 0.01
Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.
- risk 0.40cvss 7.2epss 0.02
Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution. This attack appear to be exploitable via Passing malicious PHP objection in $_POST['ssl_ipandport']. This…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at…
- risk 0.35cvss 6.5epss 0.00
Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent…
- risk 0.35cvss 6.5epss 0.00
Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a valid session before routing state-changing…
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.
- risk 0.35cvss 5.4epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the name, firstname, or username input fields.
Page 2 of 4