PT-2026-99390 · Froxlor · Froxlor

·

CVE-2026-100719

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.12
Description An issue exists in the 'DirProtections.listing' API endpoint that allows authenticated API users to retrieve htpasswd password hashes. This disclosure involves bcrypt password hashes for protected-directory users, which could facilitate offline cracking attempts and the exposure of reused credentials.
Recommendations Update to version 2.3.12 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100719
GHSA-8WFC-9QP5-GJXF

Affected Products

Froxlor