PT-2026-99391 · Froxlor · Froxlor
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Froxlor versions 2.0.0 through 2.3.10
Description
Stored cross-site scripting occurs when a user with customer privileges uploads an SSL certificate. The Certificates API
add() and update() methods use openssl x509 parse() to process the certificate and store the issuer organization issuer['O'] value without sanitization. Because the table-listing renderer uses the Twig raw filter, which disables HTML auto-escaping, the malicious value executes as a script when an administrator or reseller views the SSL certificates section. This allows a privilege escalation from a customer to an administrator, potentially leading to full account takeover. Since administrators control webserver, DNS, and PHP configurations via a root-level cron job, this can be further escalated to remote command execution as root on the server.Recommendations
Update Froxlor to version 2.3.12.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor