Froxlor是Froxlor组织开源的一款服务器管理软件。 Froxlor 2.3.8之前版本存在信息泄露漏洞,该漏洞源于API命令在返回数据库行时未移除密码和data_2fa字段,可能导致经过身份验证的API调用者获取客户、管理员和FTP密码哈希以及TOTP种子,从而接管账户或绕过双因素认证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-54347 | 8.7 HIGH | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover |
| CVE-2026-52793 | 8.1 HIGH | Froxlor: API Authentication bypasses 2FA Authentication |
| CVE-2026-54348 | 7.2 HIGH | Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Dat |
| CVE-2026-55593 | 6.5 MEDIUM | Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery |
| CVE-2026-54543 | 5.4 MEDIUM | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields |
No comments yet