PT-2026-34638 · Froxlor · Froxlor
Published
2026-04-23
·
Updated
2026-04-23
·
CVE-2026-41233
CVSS v3.1
5.4
Medium
| AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Froxlor is open source server administration software. Prior to version 2.3.6, in
Domains.add(), the adminid parameter is accepted from user input and used without validation when the calling reseller does not have the customers see all permission. This allows a reseller to attribute newly created domains to any other admin, bypassing their own domain quota (since the wrong admin's domains used counter is incremented) and potentially exhausting another admin's quota. Version 2.3.6 fixes the issue.Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor