PT-2026-34638 · Froxlor · Froxlor

Offset

·

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41233

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.6
Description In the Domains.add() function, the adminid parameter is accepted from user input without validation when the calling reseller lacks the customers see all permission. This allows a reseller to attribute newly created domains to any other administrator, bypassing their own domain quota by incrementing the domains used counter of another administrator, which may lead to the exhaustion of that administrator's quota.
Recommendations Update to version 2.3.6.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41233
GHSA-JVX4-XV3M-HRJ4

Affected Products

Froxlor