SB2026092918 - Multiple vulnerabilities in Froxlor



SB2026092918 - Multiple vulnerabilities in Froxlor

Published: September 29, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092918
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact

Breakdown by Severity

Medium 20% Low 80%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary JavaScript in an administrator's authenticated session.

The vulnerability exists due to cross-site scripting in the customer theme field and customer overview listing when an administrator with the optional Theme column enabled views a customer-controlled theme value. A remote user can submit a theme-change request containing a crafted HTML and JavaScript payload to execute arbitrary JavaScript in an administrator's authenticated session.

User interaction is required because an administrator must view the customer overview with the optional Theme column enabled.


2) CRLF injection (CVE-ID: N/A)

CWE-ID: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to inject arbitrary lines into a root-owned NSS group database.

The vulnerability exists due to improper neutralization of CRLF sequences in the additional_members parameter of the Ftps.add API when submitting a crafted additional_members value. A remote user can submit a newline-containing parameter value to inject arbitrary lines into a root-owned NSS group database.

The issue requires nssextrausers to be enabled and the FTP option to be available to customers.


3) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incorrect authorization in the MysqlServer API read commands when handling API requests for MySQL server configuration. A remote user can send an API request to disclose sensitive information.

Responses can include server management usernames, hosts, ports, captions, and TLS settings, but exclude passwords.


4) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incorrect authorization in the Cronjobs API read commands when handling API requests for cronjob information. A remote user can send an API request to disclose sensitive information.

The disclosed information can include internal cron entries, module and class names, configured intervals, active states, and last-run timestamps.


5) Authorization bypass through user-controlled key (CVE-ID: N/A)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose other administrators' email template bodies.

The vulnerability exists due to improper authorization in the email template editor in admin_templates.php when handling edit requests with a user-controlled mailbodyid. A remote user can combine an owned subjectid with a foreign mailbodyid in an edit request to disclose other administrators' email template bodies.

The save path enforces ownership checks, so foreign templates cannot be modified through this issue.


Remediation

Install update from vendor's website.