PT-2026-77319 · Froxlor · Froxlor

CVE-2026-55593

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.8
Description The standalone 'lib/ajax.php' entry point bypasses centralized request validation in 'lib/init.php'. Additionally, the Ajax::handle function in 'lib/Froxlor/Ajax/Ajax.php' only verifies a valid session before routing state-changing requests. Specifically, the editapikey action in Ajax::editApiKey updates the allowed from and valid until variables without validating a Cross-Site Request Forgery (CSRF) token—a type of attack where an unauthorized command is transmitted from a user that the web application trusts. An unauthenticated attacker can trick an authenticated administrator's browser into submitting a forged request to add an attacker-controlled address to an API key's allowed from list or remove its expiration date, thereby weakening security restrictions.
Recommendations Update to version 2.3.8.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55593
GHSA-XPR4-8VP6-C87J

Affected Products

Froxlor