Froxlor 是一款服务器管理面板。在 2.3.10 及更早版本中, 函数仅对 返回的路径(path)、查询字符串(query)和片段(fragment)组件中的回车符(CR)和换行符(LF)进行过滤,而从未检查 userinfo(即 )部分。这是对 GHSA-c3p2 漏洞的不完整修复。 具有子域名创建权限的低权限已认证客户(无需管理员权限或更改服务器设置的权限)可以提供一个带有 CR/LF 载荷的 userinfo 部分的子域名重定向 URL(例如: )。该值能够通过验证,并成功通过 IDNA 编码处理,最终
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100716 | 9.9 CRITICAL | Froxlor before 2.3.12 Privilege Escalation via Symlink |
| CVE-2026-100715 | 9.6 CRITICAL | Froxlor before 2.3.12 Arbitrary File Deletion via Symlink |
| CVE-2026-100714 | 9.1 CRITICAL | Froxlor before 2.3.12 Command Injection via letsencryptchallengepath |
| CVE-2026-100720 | 8.7 HIGH | Froxlor before 2.3.12 Stored XSS via SSL certificate issuer |
| CVE-2026-100713 | 7.8 HIGH | Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync |
| CVE-2026-100711 | 7.5 HIGH | froxlor before 2.3.12 Authentication Bypass via Session Persistence |
| CVE-2026-100709 | 7.5 HIGH | Froxlor before 2.3.12 2FA Bypass via Namespace Confusion |
| CVE-2026-100718 | 7.1 HIGH | Froxlor before 2.3.12 Authentication Bypass via EmailSender.add |
| CVE-2026-100708 | 7.1 HIGH | Froxlor before 2.3.13 Private Key Disclosure via Certificates API |
| CVE-2026-100712 | 6.5 MEDIUM | froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF |
| CVE-2026-100719 | 6.5 MEDIUM | Froxlor before 2.3.12 Credential Disclosure via DirProtections API |
| CVE-2026-100710 | 4.9 MEDIUM | Froxlor before 2.3.12 DKIM Private Key Disclosure via API |
No comments yet