Froxlor 2.0.0 至 2.3.10 版本存在存储型跨站脚本(XSS)漏洞。当客户(权限最低的认证角色)为其域名之一上传 SSL 证书时,Certificates API 的 add()/update() 方法会使用 openssl_x509_parse() 解析该证书,并将颁发机构组织字段(issuer['O'])的值未经任何 sanitization(清理/转义)地直接存储。随后,Froxlor 的表格列表渲染器通过 Twig 的 过滤器输出标量单元格,从而禁用了 HTML 自动转义机制。因此,当管理员
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100717 | 9.9 CRITICAL | froxlor before 2.3.12 CRLF Injection via validateUrl userinfo |
| CVE-2026-100716 | 9.9 CRITICAL | Froxlor before 2.3.12 Privilege Escalation via Symlink |
| CVE-2026-100715 | 9.6 CRITICAL | Froxlor before 2.3.12 Arbitrary File Deletion via Symlink |
| CVE-2026-100714 | 9.1 CRITICAL | Froxlor before 2.3.12 Command Injection via letsencryptchallengepath |
| CVE-2026-100713 | 7.8 HIGH | Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync |
| CVE-2026-100711 | 7.5 HIGH | froxlor before 2.3.12 Authentication Bypass via Session Persistence |
| CVE-2026-100709 | 7.5 HIGH | Froxlor before 2.3.12 2FA Bypass via Namespace Confusion |
| CVE-2026-100718 | 7.1 HIGH | Froxlor before 2.3.12 Authentication Bypass via EmailSender.add |
| CVE-2026-100708 | 7.1 HIGH | Froxlor before 2.3.13 Private Key Disclosure via Certificates API |
| CVE-2026-100712 | 6.5 MEDIUM | froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF |
| CVE-2026-100719 | 6.5 MEDIUM | Froxlor before 2.3.12 Credential Disclosure via DirProtections API |
| CVE-2026-100710 | 4.9 MEDIUM | Froxlor before 2.3.12 DKIM Private Key Disclosure via API |
No comments yet