โ† All reports

The Froxlor open-source server administration software has multiple security vulnerabilities in versions prior to 2.3.6 that could allow unauthorized actions such as creating arbitrary DNS records and accessing unauthorized language files.

CybersecurityTechnologyConflictApr 23, 2026score 0.173 posts ยท 0 replies across 1 instances
This thread discusses multiple security vulnerabilities in the Froxlor open-source server administration software, specifically affecting versions prior to 2.3.6. These vulnerabilities involve improper input validation and sanitization, which could lead to potential security risks such as arbitrary DNS record creation and unauthorized language file access. The vulnerabilities have been reported and are being tracked by the EUVD database.

Claims

The Froxlor open-source server administration software has multiple security vulnerabilities in versions prior to 2.3.6 that could allow unauthorized actions such as creating arbitrary DNS records and accessing unauthorized language files.
Parent: CybersecurityEntity: FroxlorImpact: negativeDate: Apr 23, 2026Target: The Froxlor open-source server administration software has multiple security vulnerabilities in versions prior to 2.3.6 that could allow unauthorized actions such as creating arbitrary DNS records and accessing unauthorized language files.

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-25176 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Froxlor ๐Ÿข Vendor: froxlor ๐Ÿ“… Updated: 2026-04-23 ๐Ÿ“ Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated cu... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25176 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25178 ๐Ÿ“Š Score: 9.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Froxlor ๐Ÿข Vendor: froxlor ๐Ÿ“… Updated: 2026-04-23 ๐Ÿ“ Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25178 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25180 ๐Ÿ“Š Score: 8.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Froxlor ๐Ÿข Vendor: froxlor ๐Ÿ“… Updated: 2026-04-23 ๐Ÿ“ Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by the if/... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25180 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability