Froxlor 2.3.7 之前的版本在 Mysqls.add API 命令中未能对 参数进行有效校验,以检查其是否属于客户被允许的 允许列表。攻击者可以提供一个不在允许列表中的服务器索引,从而在禁止使用的服务器上创建 MySQL 数据库和用户,绕过针对每个客户的访问控制机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90937 | 9.9 CRITICAL | froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL |
| CVE-2024-58383 | 7.3 HIGH | Froxlor before 2.2.0 Insecure File Permissions mysql.conf |
| CVE-2026-90936 | 4.3 MEDIUM | Froxlor before 2.3.7 Information Disclosure via customer_email.php |
No comments yet