PT-2026-99379 · Froxlor · Froxlor
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.13
Description
An issue exists where the raw PEM TLS private-key content stored in the
ssl key file column is returned verbatim in JSON responses. This occurs because results from domain ssl settings queries are processed by the ApiCommand::response() function without field stripping or an allowlist. This allows low-privileged authenticated API users to retrieve private keys for their own domains, including server-side generated Let's Encrypt keys that are normally restricted to root filesystem access. Additionally, reseller and customers see all admin accounts can extract private keys belonging to other principals via the 'Certificates.get' and 'Certificates.listing' API endpoints. Exposure of these keys can lead to domain impersonation, passive decryption of TLS traffic, and active machine-in-the-middle attacks.Recommendations
Update Froxlor to version 2.3.13 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor