Froxlor是Froxlor组织开源的一款服务器管理软件。 Froxlor 2.3.8之前版本存在输入验证错误漏洞,该漏洞源于DomainZones.add API命令未正确过滤用户输入的record和type值,导致攻击者可通过注入额外的DNS资源记录行绕过验证,修改DNS数据并可能影响DNS可用性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62988 | 9.0 CRITICAL | Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints |
| CVE-2026-54347 | 8.7 HIGH | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover |
| CVE-2026-52793 | 8.1 HIGH | Froxlor: API Authentication bypasses 2FA Authentication |
| CVE-2026-54348 | 7.2 HIGH | Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Dat |
| CVE-2026-55593 | 6.5 MEDIUM | Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery |
No comments yet