<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T13:57:51.146554+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-274211</id>
    <title>EUVD-2026-274211</title>
    <updated>2026-10-04T13:57:51.149229+00:00</updated>
    <content>EUVD-2026-274211</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-274211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26279</id>
    <title>fkie_cve-2026-26279</title>
    <updated>2026-10-04T13:57:51.149260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel.adminmail setting. This value is later concatenated into a shell command executed as root by a cron job, where the pipe character | is explicitly whitelisted. The result is full root-level Remote Code Execution. This vulnerability is fixed in 2.3.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-26279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-33mp-8p67-xj7c</id>
    <title>GHSA-33mp-8p67-xj7c — Froxlor has Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection</title>
    <updated>2026-10-04T13:57:51.149294+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: froxlor/froxlor</p>
<p>## Summary</p>
<p>A typo in Froxlor's input validation code (`==` instead of `=`) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings — including shell metacharacters — in the `panel.adminmail` setting. This value is later concatenated into a shell command executed as **root** by a cron job, where the pipe character `|` is explicitly whitelisted. The result is **full root-level Remote Code Execution**.</p>
<p>---</p>
<p>## Why This Is a Security Vulnerability (Not Just "Admin Using Admin Features")</p>
<p>Froxlor is a **shared hosting control panel**. In production deployments:</p>
<p>1. **Admin panel access does not equal root access.** Hosting providers assign the Froxlor admin role to staff who manage customer accounts, domains, and services through the web UI. These operators are not given SSH access or root shell on the underlying server. The boundary between "panel admin" and "OS root" is a deliberate security design.</p>
<p>2. **Froxlor itself enforces this boundary.** The `safe_exec()` function (FileDir.php:224-264) exists specifically to prevent shell injection — it blocks `;`, `|`, `&amp;`, `&gt;`, `&lt;`, `` ` ``, `$`, `~`, `?`. The email validation function (`validateFormFieldEmail`) exists specifically to ensure email fields contain valid emails. Both mechanisms are security boundaries that this vulnerability bypasses.</p>
<p>3. **The root cause is an unintentional code defect.** The `==` operator on a standalone l…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-33mp-8p67-xj7c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0577</id>
    <title>WID-SEC-W-2026-0577 — Froxlor: Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-04T13:57:51.149418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Froxlor ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0577"/>
  </entry>
</feed>
