PT-2026-99388 · Froxlor · Froxlor

·

CVE-2026-100717

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions froxlor versions prior to 2.3.12
Description An authenticated low-privilege customer with subdomain-create rights can inject arbitrary web-server configuration lines. The Validate::validateUrl() function fails to inspect the userinfo component of a URL for carriage return (CR) and line feed (LF) characters. By supplying a subdomain redirect URL with a CR/LF payload in the userinfo portion, an attacker can break out of the emitted directive. Since the software regenerates and reloads the web-server configuration as root, these injected directives apply server-wide, potentially allowing the attacker to hijack responses or read local files.
Recommendations Update to version 2.3.12.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100717
GHSA-GXX3-HWJC-H2GP

Affected Products

Froxlor