Incorrect authorization in Froxlor - #VU152728
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in the MysqlServer API read commands when handling API requests for MySQL server configuration. A remote user can send an API request to disclose sensitive information.
Responses can include server management usernames, hosts, ports, captions, and TLS settings, but exclude passwords.