Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Muhammadahmad62

#20586of 57,338
14.2Total CVSS
Vulnerabilities · 2
High
2
PT-2026-99389
7.1
2026-09-26
Froxlor · Froxlor · CVE-2026-100718
**Name of the Vulnerable Software and Affected Versions** Froxlor versions prior to 2.3.12 **Description** The software fails to enforce the `mail.allow external domains` policy within the 'EmailSender.add' API endpoint. When an administrator enables the allowed-sender feature but disables external allowed-sender domains (setting `mail.enable allow sender` to 1 and `mail.allow external domains` to 0), an authenticated customer with API access can use the 'EmailSender.add' endpoint to register an arbitrary external sender address. This bypasses the administrator configuration and allows customers to authorize sender identities outside their hosted domains, which can facilitate sender spoofing. **Recommendations** Update to version 2.3.12 or later.
PT-2026-99390
7.1
2026-09-26
Froxlor · Froxlor · CVE-2026-100719
**Name of the Vulnerable Software and Affected Versions** Froxlor versions prior to 2.3.12 **Description** An issue exists in the 'DirProtections.listing' API endpoint that allows authenticated API users to retrieve htpasswd password hashes. This disclosure involves bcrypt password hashes for protected-directory users, which could facilitate offline cracking attempts and the exposure of reused credentials. **Recommendations** Update to version 2.3.12 or later.