Froxlor是Froxlor组织开源的一款服务器管理软件。 Froxlor 2.3.8之前版本存在SQL注入漏洞,该漏洞源于对ipaddress数组处理不当,未强制数字元素类型且未使用参数化查询,可能导致具有change_serversettings权限的已认证管理员通过UNION-based有效载荷检索任意数据库数据(包括管理员登录名和bcrypt密码哈希),甚至造成权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-62988 | 9.0 CRITICAL | Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints |
| CVE-2026-54347 | 8.7 HIGH | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover |
| CVE-2026-52793 | 8.1 HIGH | Froxlor: API Authentication bypasses 2FA Authentication |
| CVE-2026-55593 | 6.5 MEDIUM | Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery |
| CVE-2026-54543 | 5.4 MEDIUM | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields |
No comments yet