PT-2026-99383 · Froxlor · Froxlor
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
froxlor versions prior to 2.3.12
Description
An issue exists where two-factor authentication (2FA) is disabled immediately upon a GET request to the 2FA management page, such as the endpoint '/customer index.php?page=2fa&action=delete'. This process occurs without requiring confirmation, re-authentication, or a CSRF (Cross-Site Request Forgery) token—a type of attack that forces an authenticated user to execute unwanted actions. Because the global CSRF middleware only protects POST, PUT, PATCH, and DELETE requests, and the session cookie uses SameSite=Lax, a cross-site top-level navigation can silently clear the
type 2fa and data 2fa variables. Both customer and admin 2FA handlers are affected, allowing an attacker to reduce an account to password-only authentication if a logged-in user follows a crafted link.Recommendations
Update froxlor to version 2.3.12.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor