PT-2026-99390 · Froxlor · Froxlor
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.12
Description
An issue exists in the 'DirProtections.listing' API endpoint that allows authenticated API users to retrieve htpasswd password hashes. This disclosure involves bcrypt password hashes for protected-directory users, which could facilitate offline cracking attempts and the exposure of reused credentials.
Recommendations
Update to version 2.3.12 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor