PT-2026-77303 · Froxlor · Froxlor
CVE-2026-62988
·
Published
2026-08-18
·
Updated
2026-08-21
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Froxlor versions 2.3.7 through 2.3.7
Description
Certain API commands retrieve full database rows and return them without removing sensitive fields. An authenticated API caller with appropriate permissions can obtain password hashes and Base32-encoded TOTP (Time-based One-Time Password) seeds for customer, administrator, and FTP accounts. This exposure allows for offline password cracking and the generation of valid second-factor codes, potentially leading to a full takeover of the hosting panel or hosted resources.
API Endpoints: 'Customers.get', 'Customers.listing', 'Admins.get', 'Admins.listing', 'Ftps.get', and 'Ftps.listing'
Vulnerable Parameters or Variables:
password and data 2faRecommendations
Update to version 2.3.8.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor