Froxlor是Froxlor团队的一套轻量级服务器管理软件。 Froxlor 2.3.6之前版本存在安全漏洞,该漏洞源于EmailSender::add()中域所有权验证使用了错误的数组索引,导致任何经过身份验证的客户可以为其他客户的域添加发件人别名。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41228 | 10.0 CRITICAL | Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that l |
| CVE-2026-41229 | 9.1 CRITICAL | Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generatio |
| CVE-2026-41230 | 8.5 HIGH | Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones:: |
| CVE-2026-41231 | 7.5 HIGH | Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Director |
| CVE-2026-41233 | 5.4 MEDIUM | Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.ad |
No comments yet