Vendor CVEs
Froxlor
All CVEs
77 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0315 | Hig | 0.61 | 8.8 | 0.98 | Jan 16, 2023 | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. | ||
| CVE-2021-42325 | Cri | 0.61 | 9.8 | 0.12 | Oct 12, 2021 | Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name. | ||
| CVE-2026-100717 | Cri | 0.57 | 9.9 | — | Sep 26, 2026 | froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This… | ||
| CVE-2026-100716 | Cri | 0.57 | 9.9 | — | Sep 26, 2026 | Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that… | ||
| CVE-2026-90937 | Cri | 0.57 | 9.9 | 0.00 | Sep 14, 2026 | froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost… | ||
| CVE-2026-41228 | Cri | 0.57 | 9.9 | 0.01 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set… | ||
| CVE-2023-6069 | Cri | 0.57 | 9.9 | 0.01 | Nov 10, 2023 | Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0. | ||
| CVE-2023-3173 | Cri | 0.57 | 9.8 | 0.01 | Jun 9, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20. | ||
| CVE-2023-1307 | Cri | 0.57 | 9.8 | 0.01 | Mar 10, 2023 | Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13. | ||
| CVE-2015-5959 | Cri | 0.57 | 9.8 | 0.03 | Sep 6, 2017 | Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log. | ||
| CVE-2016-5100 | Cri | 0.57 | 9.8 | 0.02 | Feb 13, 2017 | Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value. | ||
| CVE-2023-2034 | Hig | 0.56 | 8.8 | 0.71 | Apr 14, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14. | ||
| CVE-2026-100715 | Cri | 0.55 | 9.6 | — | Sep 26, 2026 | Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink… | ||
| CVE-2024-34070 | Cri | 0.55 | 9.6 | 0.01 | May 14, 2024 | Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the… | ||
| CVE-2026-100714 | Cri | 0.52 | 9.1 | — | Sep 26, 2026 | Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in… | ||
| CVE-2026-62988 | Cri | 0.52 | 9.0 | 0.01 | Aug 18, 2026 | Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Commands/Admins.php, and… | ||
| CVE-2026-41229 | Cri | 0.52 | 9.1 | 0.01 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission adds or updates a… | ||
| CVE-2026-26279 | Cri | 0.52 | 9.1 | 0.01 | Mar 3, 2026 | Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary… | ||
| CVE-2023-0877 | Hig | 0.51 | 8.8 | 0.04 | Feb 17, 2023 | Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11. | ||
| CVE-2026-100720 | Hig | 0.50 | 8.7 | — | Sep 26, 2026 | Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store… | ||
| CVE-2026-54347 | Hig | 0.50 | 8.7 | 0.00 | Aug 18, 2026 | Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::wordwrap without HTML… | ||
| CVE-2026-41236 | Hig | 0.50 | 8.8 | 0.01 | Jun 4, 2026 | Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` under a customer-controlled… | ||
| CVE-2026-30932 | Hig | 0.50 | 8.8 | 0.01 | Mar 24, 2026 | Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and… | ||
| CVE-2023-1033 | Hig | 0.50 | 8.8 | 0.00 | Feb 25, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11. | ||
| CVE-2023-0671 | Hig | 0.50 | 8.8 | 0.01 | Feb 4, 2023 | Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10. | ||
| CVE-2020-10235 | Hig | 0.50 | 8.8 | 0.02 | Mar 9, 2020 | An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in… | ||
| CVE-2026-41237 | Hig | 0.49 | — | 0.00 | Jun 4, 2026 | Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input… | ||
| CVE-2026-41235 | Hig | 0.49 | — | 0.00 | Jun 4, 2026 | Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enforce that whitelist when… | ||
| CVE-2026-41230 | Hig | 0.48 | 8.5 | 0.01 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by the if/elseif validation… | ||
| CVE-2026-52793 | Hig | 0.46 | 8.1 | 0.00 | Aug 18, 2026 | Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an administrator or customer account without checking type_2fa, validating a TOTP… | ||
| CVE-2026-100713 | Hig | 0.44 | 7.8 | — | Sep 26, 2026 | Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile()… | ||
| CVE-2026-100711 | Hig | 0.42 | 7.5 | — | Sep 26, 2026 | froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing… | ||
| CVE-2026-100709 | Hig | 0.42 | 7.5 | — | Sep 26, 2026 | Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and… | ||
| CVE-2026-41234 | Hig | 0.42 | 7.6 | 0.00 | Jun 4, 2026 | Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which… | ||
| CVE-2026-41231 | Hig | 0.42 | 7.5 | 0.01 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` parameter to `FileDir::makeCorrectDir()`, bypassing the symlink validation that… | ||
| CVE-2020-36978 | Med | 0.42 | 6.4 | 0.00 | Jan 27, 2026 | Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer… | ||
| CVE-2023-50256 | Hig | 0.42 | 7.5 | 0.01 | Jan 3, 2024 | Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory… | ||
| CVE-2023-2666 | Hig | 0.42 | 7.5 | 0.01 | May 12, 2023 | Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16. | ||
| CVE-2018-12642 | Hig | 0.42 | 7.5 | 0.01 | Jun 22, 2018 | Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user. | ||
| CVE-2024-58383 | Hig | 0.40 | 7.3 | 0.00 | Sep 14, 2026 | Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are… | ||
| CVE-2026-54348 | Hig | 0.40 | 7.2 | 0.01 | Aug 18, 2026 | Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enforcing numeric element types.… | ||
| CVE-2023-3668 | Hig | 0.40 | 7.2 | 0.01 | Jul 14, 2023 | Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21. | ||
| CVE-2023-3172 | Hig | 0.40 | 7.2 | 0.01 | Jun 9, 2023 | Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20. | ||
| CVE-2018-1000527 | Hig | 0.40 | 7.2 | 0.03 | Jun 26, 2018 | Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution. This attack appear to be exploitable via Passing malicious PHP objection in $_POST['ssl_ipandport']. This… | ||
| CVE-2026-100718 | Hig | 0.39 | 7.1 | — | Sep 26, 2026 | Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external allowed-sender domains (mail.enable_allow_sender = 1, mail.allow_external_domains… | ||
| CVE-2026-100708 | Hig | 0.39 | 7.1 | — | Sep 26, 2026 | Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_settings queries are… | ||
| CVE-2020-10237 | Med | 0.36 | 5.5 | 0.00 | Mar 9, 2020 | An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at… | ||
| CVE-2026-100719 | Med | 0.35 | 6.5 | — | Sep 26, 2026 | Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcrypt password hashes for protected-directory users, enabling offline cracking… | ||
| CVE-2026-100712 | Med | 0.35 | 6.5 | — | Sep 26, 2026 | froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET request to the 2FA management page (e.g. /customer_index.php?page=2fa&action=delete), with no confirmation, re-authentication, or CSRF token. The global CSRF… | ||
| CVE-2026-90767 | Med | 0.35 | 6.5 | 0.00 | Sep 13, 2026 | Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent… |
- risk 0.61cvss 8.8epss 0.98
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
- risk 0.61cvss 9.8epss 0.12
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
- risk 0.57cvss 9.9epss —
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This…
- risk 0.57cvss 9.9epss —
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that…
- risk 0.57cvss 9.9epss 0.00
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost…
- risk 0.57cvss 9.9epss 0.01
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set…
- risk 0.57cvss 9.9epss 0.01
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
- risk 0.57cvss 9.8epss 0.01
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
- risk 0.57cvss 9.8epss 0.01
Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.
- risk 0.57cvss 9.8epss 0.03
Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.
- risk 0.57cvss 9.8epss 0.02
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.
- risk 0.56cvss 8.8epss 0.71
Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.
- risk 0.55cvss 9.6epss —
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink…
- risk 0.55cvss 9.6epss 0.01
Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the…
- risk 0.52cvss 9.1epss —
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in…
- risk 0.52cvss 9.0epss 0.01
Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Commands/Admins.php, and…
- risk 0.52cvss 9.1epss 0.01
Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission adds or updates a…
- risk 0.52cvss 9.1epss 0.01
Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary…
- risk 0.51cvss 8.8epss 0.04
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.
- risk 0.50cvss 8.7epss —
Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store…
- risk 0.50cvss 8.7epss 0.00
Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::wordwrap without HTML…
- risk 0.50cvss 8.8epss 0.01
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` under a customer-controlled…
- risk 0.50cvss 8.8epss 0.01
Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and…
- risk 0.50cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11.
- risk 0.50cvss 8.8epss 0.01
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.
- risk 0.50cvss 8.8epss 0.02
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in…
- risk 0.49cvss —epss 0.00
Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input…
- risk 0.49cvss —epss 0.00
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enforce that whitelist when…
- risk 0.48cvss 8.5epss 0.01
Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by the if/elseif validation…
- risk 0.46cvss 8.1epss 0.00
Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an administrator or customer account without checking type_2fa, validating a TOTP…
- risk 0.44cvss 7.8epss —
Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile()…
- risk 0.42cvss 7.5epss —
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing…
- risk 0.42cvss 7.5epss —
Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and…
- risk 0.42cvss 7.6epss 0.00
Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which…
- risk 0.42cvss 7.5epss 0.01
Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` parameter to `FileDir::makeCorrectDir()`, bypassing the symlink validation that…
- risk 0.42cvss 6.4epss 0.00
Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer…
- risk 0.42cvss 7.5epss 0.01
Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory…
- risk 0.42cvss 7.5epss 0.01
Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.
- risk 0.42cvss 7.5epss 0.01
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
- risk 0.40cvss 7.3epss 0.00
Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are…
- risk 0.40cvss 7.2epss 0.01
Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enforcing numeric element types.…
- risk 0.40cvss 7.2epss 0.01
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
- risk 0.40cvss 7.2epss 0.01
Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.
- risk 0.40cvss 7.2epss 0.03
Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution. This attack appear to be exploitable via Passing malicious PHP objection in $_POST['ssl_ipandport']. This…
- risk 0.39cvss 7.1epss —
Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external allowed-sender domains (mail.enable_allow_sender = 1, mail.allow_external_domains…
- risk 0.39cvss 7.1epss —
Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_settings queries are…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at…
- risk 0.35cvss 6.5epss —
Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcrypt password hashes for protected-directory users, enabling offline cracking…
- risk 0.35cvss 6.5epss —
froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET request to the 2FA management page (e.g. /customer_index.php?page=2fa&action=delete), with no confirmation, re-authentication, or CSRF token. The global CSRF…
- risk 0.35cvss 6.5epss 0.00
Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent…
Page 1 of 2