PT-2026-34638 · Froxlor · Froxlor

Published

2026-04-23

·

Updated

2026-04-23

·

CVE-2026-41233

CVSS v3.1

5.4

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Froxlor is open source server administration software. Prior to version 2.3.6, in Domains.add(), the adminid parameter is accepted from user input and used without validation when the calling reseller does not have the customers see all permission. This allows a reseller to attribute newly created domains to any other admin, bypassing their own domain quota (since the wrong admin's domains used counter is incremented) and potentially exhausting another admin's quota. Version 2.3.6 fixes the issue.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-41233

Affected Products

Froxlor