PT-2026-77301 · Froxlor · Froxlor
CVE-2026-54543
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.8
Description
The
DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php fails to properly sanitize user-controlled record and type values. It does not reject line delimiters, tab characters, semicolons, or unsupported DNS record types before lib/Froxlor/Dns/DnsEntry.php serializes these values into a BIND zone file. An authenticated customer with DNS-zone permissions can inject crafted values into the record field or the type field to create additional resource-record lines, bypassing field-level validation. This allows the modification of DNS data and may impact DNS availability within a zone the user is authorized to manage.Recommendations
Update to version 2.3.8.
Avoid using the
record and type parameters in the DomainZones.add API command until the update is applied.Exploit
Fix
Special Elements Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Froxlor