The Froxlor open-source server administration software has multiple security vulnerabilities in versions prior to 2.3.6 that could allow unauthorized actions such as creating arbitrary DNS records and accessing unauthorized language files.
Claims
The Froxlor open-source server administration software has multiple security vulnerabilities in versions prior to 2.3.6 that could allow unauthorized actions such as creating arbitrary DNS records and accessing unauthorized language files.
Parent: CybersecurityEntity: FroxlorImpact: negativeDate: Apr 23, 2026Target: The Froxlor open-source server administration software has multiple security vulnerabilities in versions prior to 2.3.6 that could allow unauthorized actions such as creating arbitrary DNS records and accessing unauthorized language files.
Source posts
๐จ EUVD-2026-25176
๐ Score: 10.0/10 (CVSS v3.1)
๐ฆ Product: Froxlor
๐ข Vendor: froxlor
๐
Updated: 2026-04-23
๐ Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated cu...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25176
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25178
๐ Score: 9.1/10 (CVSS v3.1)
๐ฆ Product: Froxlor
๐ข Vendor: froxlor
๐
Updated: 2026-04-23
๐ Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25178
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25180
๐ Score: 8.5/10 (CVSS v3.1)
๐ฆ Product: Froxlor
๐ข Vendor: froxlor
๐
Updated: 2026-04-23
๐ Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by the if/...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25180
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability