Описание
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint Customers.update (and Admins.update) does not validate the def_language parameter against the list of available language files. An authenticated customer can set def_language to a path traversal payload (e.g., ../../../../../var/customers/webs/customer1/evil), which is stored in the database. On subsequent requests, Language::loadLanguage() constructs a file path using this value and executes it via require, achieving arbitrary PHP code execution as the web server user. Version 2.3.6 fixes the issue.
Ссылки
- Patch
- Release Notes
- ExploitMitigationVendor Advisory
- ExploitMitigationVendor Advisory
Уязвимые конфигурации
EPSS
9.9 Critical
CVSS3
Дефекты
Связанные уязвимости
Froxlor is open source server administration software. Prior to versio ...
Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution
EPSS
9.9 Critical
CVSS3