Security: froxlor/froxlor
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
TLS private key disclosure via Certificates.get/listing API (ssl_key_file returned unfiltered)GHSA-6q2v-jjq5-m2c8 published
Sep 6, 2026 by d00pHigh -
Froxlor remembered-2FA account namespace confusionGHSA-9fq7-9w8p-c3qh published
Sep 6, 2026 by d00pHigh -
Sensitive information disclosure (DKIM private key) via Domains/SubDomains APIGHSA-79gx-h528-j9xf published
Sep 6, 2026 by d00pModerate -
Password change does not invalidate existing panel sessions, API keys, or 2FA trust cookiesGHSA-57wv-g7m3-hmff published
Sep 6, 2026 by d00pModerate -
Two-factor authentication can be disabled by a cross-site GET request (state-changing action outside CSRF protection)GHSA-w582-7wqv-62mm published
Sep 6, 2026 by d00pModerate -
SSH-key sync cron re-resolves the authorized_keys path at write time — customer wins a race to append their key to root's authorized_keys (residual of GHSA-mq5v)GHSA-927x-9jfh-mq42 published
Sep 6, 2026 by d00pHigh -
`system.letsencryptchallengepath` setting is concatenated unescaped into the root cron's acme.sh command line (admin→root argument injection)GHSA-3w4g-cmpj-rj42 published
Sep 6, 2026 by d00pHigh -
FTP-data deletion cron task runs `rm -rf` as root through customer-planted symlinks (no containment check at cron time)GHSA-px4q-2rf7-cvcf published
Sep 6, 2026 by d00pHigh -
DataDump export cron follows intermediate symlinks — customer gains ownership of arbitrary directories via root `chown -R` (incomplete fix of GHSA-75h4)GHSA-2wjc-6mgx-hq42 published
Sep 6, 2026 by d00pHigh -
Incomplete fix of GHSA-c3p2 - validateUrl rejects CR/LF only in path/query/fragment, not in the userinfoGHSA-gxx3-hwjc-h2gp published
Sep 6, 2026 by d00pCritical
Learn more about advisories related to froxlor/froxlor in the GitHub Advisory Database