<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T04:58:44.833168+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277339</id>
    <title>EUVD-2026-277339</title>
    <updated>2026-10-10T04:58:44.835554+00:00</updated>
    <content>EUVD-2026-277339</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30932</id>
    <title>fkie_cve-2026-30932</title>
    <updated>2026-10-10T04:58:44.835585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. $INCLUDE) into the zone file that gets written to disk when the DNS rebuild cron job runs. This issue has been patched in version 2.3.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-30932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x6w6-2xwp-3jh6</id>
    <title>GHSA-x6w6-2xwp-3jh6 — Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API</title>
    <updated>2026-10-10T04:58:44.835617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: froxlor/froxlor</p>
<p>## Summary</p>
<p>The `DomainZones.add` API endpoint (accessible to customers with DNS enabled) does not validate the `content` field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. `$INCLUDE`) into the zone file that gets written to disk when the DNS rebuild cron job runs.</p>
<p>## Affected Code</p>
<p>`lib/Froxlor/Api/Commands/DomainZones.php`, lines 213-214, 253-254, 290-291, 292-293:</p>
<p>```php
} elseif ($type == 'LOC' &amp;&amp; !empty($content)) {
    $content = $content; // no validation
} ...
} elseif ($type == 'RP' &amp;&amp; !empty($content)) {
    $content = $content; // no validation
} ...
} elseif ($type == 'SSHFP' &amp;&amp; !empty($content)) {
    $content = $content; // no validation
} elseif ($type == 'TLSA' &amp;&amp; !empty($content)) {
    $content = $content; // no validation
}
```</p>
<p>There is even a TODO comment at line 148 acknowledging this gap:
```php
// TODO regex validate content for invalid characters
```</p>
<p>The content is then written directly into the BIND zone file via `DnsEntry::__toString()` (line 83 of `lib/Froxlor/Dns/DnsEntry.php`):</p>
<p>```php
return $this-&gt;record . "\t" . $this-&gt;ttl . "\t" . $this-&gt;class . "\t" . $this-&gt;type . "\t" ... . $_content . PHP_EOL;
```</p>
<p>And the zone file is written to disk in `lib/Froxlor/Cron/Dns/Bind.php` line 121:</p>
<p>```php
fwrite($zonefile_handler, $zoneContent . $subzones);
```</p>
<p>## PoC</p>
<p>As a customer with DNS management enabled and an API key, add a LOC record with injected BIND directives:</p>
<p>```…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x6w6-2xwp-3jh6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0834</id>
    <title>WID-SEC-W-2026-0834 — Froxlor: Schwachstelle ermöglicht Manipulation von Dateien und Offenlegung von Informationen</title>
    <updated>2026-10-10T04:58:44.835670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann eine Schwachstelle in Froxlor ausnutzen, um Dateien zu manipulieren, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0834"/>
  </entry>
</feed>
