Incorrect authorization in Froxlor - #VU152729
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in the Cronjobs API read commands when handling API requests for cronjob information. A remote user can send an API request to disclose sensitive information.
The disclosed information can include internal cron entries, module and class names, configured intervals, active states, and last-run timestamps.