Authorization bypass through user-controlled key in Froxlor - #VU152730

 

Authorization bypass through user-controlled key in Froxlor - #VU152730

Published: September 29, 2026


Vulnerability identifier: #VU152730
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose other administrators' email template bodies.

The vulnerability exists due to improper authorization in the email template editor in admin_templates.php when handling edit requests with a user-controlled mailbodyid. A remote user can combine an owned subjectid with a foreign mailbodyid in an edit request to disclose other administrators' email template bodies.

The save path enforces ownership checks, so foreign templates cannot be modified through this issue.


Affected software

Froxlor

Remediation

Install security update from vendor's website.

Froxlor - update to 2.3.14

External References

Related Security Bulletins