Incorrect authorization in Froxlor - CVE-2026-41233
Published: April 27, 2026
Froxlor
Detailed vulnerability description
The vulnerability allows a remote user to bypass domain quotas and cause a denial of service.
The vulnerability exists due to incorrect authorization in Domains.add() in lib/Froxlor/Api/Commands/Domains.php when handling the adminid parameter from API requests. A remote user can supply a crafted adminid value to bypass domain quotas and cause a denial of service.
This issue affects resellers without the customers_see_all permission and can associate newly created domains with a different admin, making the domains invisible to the reseller in listings while remaining active on the server.