PT-2026-99381 · Froxlor · Froxlor
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.12
Description
Certain API responses fail to filter sensitive columns, allowing an authenticated non-superadmin admin with the
customers see all flag to access the panel domains.dkim privkey field. This occurs when the Domains::get(), Domains::listing(), SubDomains::get(), and the admin branch of SubDomains::listing() functions perform a wildcard SELECT over the panel domains table and return the row unmodified. An attacker can use these disclosed DKIM private signing keys to sign emails that pass DKIM verification and DMARC alignment for the affected domains.Recommendations
Update to version 2.3.12.
As a temporary mitigation, restrict the use of the
customers see all flag for non-superadmin accounts.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor