Froxlor是Froxlor团队的一套轻量级服务器管理软件。 Froxlor 2.3.6之前版本存在安全漏洞,该漏洞源于API端点Customers.update和Admins.update未验证def_language参数,允许经过身份验证的客户设置路径遍历载荷,导致任意PHP代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41229 | 9.1 CRITICAL | Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generatio |
| CVE-2026-41230 | 8.5 HIGH | Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones:: |
| CVE-2026-41231 | 7.5 HIGH | Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Director |
| CVE-2026-41233 | 5.4 MEDIUM | Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.ad |
| CVE-2026-41232 | 5.0 MEDIUM | Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allow |
No comments yet