Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41232

Опубликовано: 23 апр. 2026
Источник: nvd
CVSS3: 5
EPSS Низкий

Описание

Froxlor is open source server administration software. Prior to version 2.3.6, in EmailSender::add(), the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to validateLocalDomainOwnership(). This causes the ownership check to always pass for non-existent "domains," allowing any authenticated customer to add sender aliases for email addresses on domains belonging to other customers. Postfix's sender_login_maps then authorizes the attacker to send emails as those addresses. Version 2.3.6 fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*
Версия до 2.3.6 (исключая)

EPSS

Процентиль: 14%
0.00231
Низкий

5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5
debian
4 месяца назад

Froxlor is open source server administration software. Prior to versio ...

CVSS3: 5
github
4 месяца назад

Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofing

EPSS

Процентиль: 14%
0.00231
Низкий

5 Medium

CVSS3

Дефекты

CWE-863