PT-2026-77319 · Froxlor · Froxlor
CVE-2026-55593
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.8
Description
The standalone 'lib/ajax.php' entry point bypasses centralized request validation in 'lib/init.php'. Additionally, the
Ajax::handle function in 'lib/Froxlor/Ajax/Ajax.php' only verifies a valid session before routing state-changing requests. Specifically, the editapikey action in Ajax::editApiKey updates the allowed from and valid until variables without validating a Cross-Site Request Forgery (CSRF) token—a type of attack where an unauthorized command is transmitted from a user that the web application trusts. An unauthenticated attacker can trick an authenticated administrator's browser into submitting a forged request to add an attacker-controlled address to an API key's allowed from list or remove its expiration date, thereby weakening security restrictions.Recommendations
Update to version 2.3.8.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor