Froxlor是Froxlor组织开源的一款服务器管理软件。 Froxlor 2.3.8之前版本存在跨站脚本漏洞,该漏洞源于DNS TXT记录内容包含HTML特殊字符且未进行HTML转义,可能导致具有DNS编辑器访问权限的已认证用户存储含JavaScript的内容,当管理员查看时自动执行,暴露会话数据或执行特权面板操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-62988 | 9.0 CRITICAL | Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints |
| CVE-2026-52793 | 8.1 HIGH | Froxlor: API Authentication bypasses 2FA Authentication |
| CVE-2026-54348 | 7.2 HIGH | Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Dat |
| CVE-2026-55593 | 6.5 MEDIUM | Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery |
| CVE-2026-54543 | 5.4 MEDIUM | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields |
No comments yet