Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41228

Опубликовано: 23 апр. 2026
Источник: nvd
CVSS3: 9.9
EPSS Низкий

Описание

Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint Customers.update (and Admins.update) does not validate the def_language parameter against the list of available language files. An authenticated customer can set def_language to a path traversal payload (e.g., ../../../../../var/customers/webs/customer1/evil), which is stored in the database. On subsequent requests, Language::loadLanguage() constructs a file path using this value and executes it via require, achieving arbitrary PHP code execution as the web server user. Version 2.3.6 fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*
Версия до 2.3.6 (исключая)

EPSS

Процентиль: 42%
0.00524
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-98

Связанные уязвимости

CVSS3: 9.9
debian
4 месяца назад

Froxlor is open source server administration software. Prior to versio ...

CVSS3: 9.9
github
4 месяца назад

Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution

EPSS

Процентиль: 42%
0.00524
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-98