Code Injection in Froxlor - CVE-2026-41229
Published: April 27, 2026
Froxlor
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper control of code generation in PhpHelper::parseArrayToString() when generating lib/userdata.inc.php from MysqlServer API input. A remote privileged user can supply a specially crafted privileged_user parameter to execute arbitrary code.
The injected code is loaded on every subsequent request through Database::getDB(), and exploitation can be performed by setting test_connection=0 to skip MySQL connection validation.