Incorrect authorization in Froxlor - #VU152728

 

Incorrect authorization in Froxlor - #VU152728

Published: September 29, 2026


Vulnerability identifier: #VU152728
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incorrect authorization in the MysqlServer API read commands when handling API requests for MySQL server configuration. A remote user can send an API request to disclose sensitive information.

Responses can include server management usernames, hosts, ports, captions, and TLS settings, but exclude passwords.


Affected software

Froxlor

Remediation

Install security update from vendor's website.

Froxlor - update to 2.3.14

External References

Related Security Bulletins