PT-2026-77303 · Froxlor · Froxlor

CVE-2026-62988

·

Published

2026-08-18

·

Updated

2026-08-21

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Froxlor versions 2.3.7 through 2.3.7
Description Certain API commands retrieve full database rows and return them without removing sensitive fields. An authenticated API caller with appropriate permissions can obtain password hashes and Base32-encoded TOTP (Time-based One-Time Password) seeds for customer, administrator, and FTP accounts. This exposure allows for offline password cracking and the generation of valid second-factor codes, potentially leading to a full takeover of the hosting panel or hosted resources.
API Endpoints: 'Customers.get', 'Customers.listing', 'Admins.get', 'Admins.listing', 'Ftps.get', and 'Ftps.listing'
Vulnerable Parameters or Variables: password and data 2fa
Recommendations Update to version 2.3.8.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62988
GHSA-7788-GHFQ-C6MH

Affected Products

Froxlor