PT-2026-99383 · Froxlor · Froxlor

·

CVE-2026-100712

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions froxlor versions prior to 2.3.12
Description An issue exists where two-factor authentication (2FA) is disabled immediately upon a GET request to the 2FA management page, such as the endpoint '/customer index.php?page=2fa&action=delete'. This process occurs without requiring confirmation, re-authentication, or a CSRF (Cross-Site Request Forgery) token—a type of attack that forces an authenticated user to execute unwanted actions. Because the global CSRF middleware only protects POST, PUT, PATCH, and DELETE requests, and the session cookie uses SameSite=Lax, a cross-site top-level navigation can silently clear the type 2fa and data 2fa variables. Both customer and admin 2FA handlers are affected, allowing an attacker to reduce an account to password-only authentication if a logged-in user follows a crafted link.
Recommendations Update froxlor to version 2.3.12.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100712
GHSA-W582-7WQV-62MM

Affected Products

Froxlor