PT-2026-77301 · Froxlor · Froxlor

CVE-2026-54543

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.8
Description The DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php fails to properly sanitize user-controlled record and type values. It does not reject line delimiters, tab characters, semicolons, or unsupported DNS record types before lib/Froxlor/Dns/DnsEntry.php serializes these values into a BIND zone file. An authenticated customer with DNS-zone permissions can inject crafted values into the record field or the type field to create additional resource-record lines, bypassing field-level validation. This allows the modification of DNS data and may impact DNS availability within a zone the user is authorized to manage.
Recommendations Update to version 2.3.8. Avoid using the record and type parameters in the DomainZones.add API command until the update is applied.

Exploit

Fix

Special Elements Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54543
GHSA-5RW4-4665-CVWF

Affected Products

Froxlor