Froxlor 2.3.10 及之前版本在存储“记住的 2FA 令牌”(panel_2fa_tokens)时,仅保存数值型用户 ID,未记录账户命名空间。登录时,对“记住的令牌”的查找过程未限制为特定账户类型(如客户或管理员)。由于客户和管理员的 ID 分别在不同的命名空间中分配,因此,某个 ID 合法发放给某位客户的“记住的 2FA 令牌”,也会匹配到具有相同 ID 的管理员账户。攻击者若能控制一个 ID 与之碰撞的客户账户,持有该客户有效的“记住的 2FA”Cookie,并且已知目标管理员的密码,即可绕过管理员
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100717 | 9.9 CRITICAL | froxlor before 2.3.12 CRLF Injection via validateUrl userinfo |
| CVE-2026-100716 | 9.9 CRITICAL | Froxlor before 2.3.12 Privilege Escalation via Symlink |
| CVE-2026-100715 | 9.6 CRITICAL | Froxlor before 2.3.12 Arbitrary File Deletion via Symlink |
| CVE-2026-100714 | 9.1 CRITICAL | Froxlor before 2.3.12 Command Injection via letsencryptchallengepath |
| CVE-2026-100720 | 8.7 HIGH | Froxlor before 2.3.12 Stored XSS via SSL certificate issuer |
| CVE-2026-100713 | 7.8 HIGH | Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync |
| CVE-2026-100711 | 7.5 HIGH | froxlor before 2.3.12 Authentication Bypass via Session Persistence |
| CVE-2026-100718 | 7.1 HIGH | Froxlor before 2.3.12 Authentication Bypass via EmailSender.add |
| CVE-2026-100708 | 7.1 HIGH | Froxlor before 2.3.13 Private Key Disclosure via Certificates API |
| CVE-2026-100712 | 6.5 MEDIUM | froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF |
| CVE-2026-100719 | 6.5 MEDIUM | Froxlor before 2.3.12 Credential Disclosure via DirProtections API |
| CVE-2026-100710 | 4.9 MEDIUM | Froxlor before 2.3.12 DKIM Private Key Disclosure via API |
No comments yet