Froxlor是Froxlor组织开源的一款服务器管理软件。 Froxlor 2.3.8之前版本存在跨站请求伪造漏洞,该漏洞源于lib/ajax.php入口点绕过集中请求验证,editapikey操作未验证CSRF令牌,可能导致跨站请求伪造,攻击者诱导已认证管理员浏览器提交伪造请求,添加攻击者控制的地址到API密钥的allowed_from列表或移除其过期时间,削弱密钥安全限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62988 | 9.0 CRITICAL | Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints |
| CVE-2026-54347 | 8.7 HIGH | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover |
| CVE-2026-52793 | 8.1 HIGH | Froxlor: API Authentication bypasses 2FA Authentication |
| CVE-2026-54348 | 7.2 HIGH | Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Dat |
| CVE-2026-54543 | 5.4 MEDIUM | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields |
No comments yet