CRLF injection in Froxlor - #VU152727

 

CRLF injection in Froxlor - #VU152727

Published: September 29, 2026


Vulnerability identifier: #VU152727
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-93
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject arbitrary lines into a root-owned NSS group database.

The vulnerability exists due to improper neutralization of CRLF sequences in the additional_members parameter of the Ftps.add API when submitting a crafted additional_members value. A remote user can submit a newline-containing parameter value to inject arbitrary lines into a root-owned NSS group database.

The issue requires nssextrausers to be enabled and the FTP option to be available to customers.


Affected software

Froxlor

Remediation

Install security update from vendor's website.

Froxlor - update to 2.3.14

External References

Related Security Bulletins