PT-2026-99391 · Froxlor · Froxlor

·

CVE-2026-100720

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Froxlor versions 2.0.0 through 2.3.10
Description Stored cross-site scripting occurs when a user with customer privileges uploads an SSL certificate. The Certificates API add() and update() methods use openssl x509 parse() to process the certificate and store the issuer organization issuer['O'] value without sanitization. Because the table-listing renderer uses the Twig raw filter, which disables HTML auto-escaping, the malicious value executes as a script when an administrator or reseller views the SSL certificates section. This allows a privilege escalation from a customer to an administrator, potentially leading to full account takeover. Since administrators control webserver, DNS, and PHP configurations via a root-level cron job, this can be further escalated to remote command execution as root on the server.
Recommendations Update Froxlor to version 2.3.12.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100720
GHSA-89VJ-GQQR-73P8

Affected Products

Froxlor