PT-2026-34633 · Froxlor · Froxlor

Offset

·

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41229

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.6
Description The PhpHelper::parseArrayToString() function writes string values into single-quoted PHP string literals without escaping single quotes. An administrator with change serversettings permission can exploit this by adding or updating a MySQL server via the API. The privileged user parameter lacks input validation and is written unescaped into the lib/userdata.inc.php file. Because this file is required on every request via Database::getDB(), it allows the injection of arbitrary PHP code that executes as the web server user on every subsequent page load.
Recommendations Update to version 2.3.6.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41229
GHSA-GC9W-CC93-RJV8

Affected Products

Froxlor