Описание
Froxlor is open source server administration software. Prior to version 2.3.6, in Domains.add(), the adminid parameter is accepted from user input and used without validation when the calling reseller does not have the customers_see_all permission. This allows a reseller to attribute newly created domains to any other admin, bypassing their own domain quota (since the wrong admin's domains_used counter is incremented) and potentially exhausting another admin's quota. Version 2.3.6 fixes the issue.
Ссылки
- Patch
- Release Notes
- ExploitMitigationVendor Advisory
- ExploitMitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.6 (исключая)
cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00264
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 5.4
debian
4 месяца назад
Froxlor is open source server administration software. Prior to versio ...
CVSS3: 5.4
github
4 месяца назад
Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()
EPSS
Процентиль: 18%
0.00264
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-863