Authorization bypass through user-controlled key in Froxlor - #VU152730
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose other administrators' email template bodies.
The vulnerability exists due to improper authorization in the email template editor in admin_templates.php when handling edit requests with a user-controlled mailbodyid. A remote user can combine an owned subjectid with a foreign mailbodyid in an edit request to disclose other administrators' email template bodies.
The save path enforces ownership checks, so foreign templates cannot be modified through this issue.