<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:02:24.377823+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-356487</id>
    <title>EUVD-2026-356487</title>
    <updated>2026-10-03T12:02:24.426499+00:00</updated>
    <content>EUVD-2026-356487</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-356487"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54347</id>
    <title>fkie_cve-2026-54347</title>
    <updated>2026-10-03T12:02:24.426535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::wordwrap without HTML escaping, and templates/Froxlor/table/table.html.twig renders the callback result with the raw filter. An authenticated customer with DNS editor access can store JavaScript-bearing content in a TXT record. When an administrator views the affected domain's DNS configuration, the payload executes automatically in the administrator's browser session, which can expose session data or perform privileged panel actions. This issue is fixed in version 2.3.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54347"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-43gm-9rr3-cx7g</id>
    <title>GHSA-43gm-9rr3-cx7g — Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover</title>
    <updated>2026-10-03T12:02:24.426572+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: froxlor/froxlor</p>
<p>### Summary</p>
<p>A stored Cross-Site Scripting (XSS) vulnerability in Froxlor's DNS editor allows an authenticated user with DNS editor access (customer role) to inject arbitrary JavaScript into any administrator's browser session. When an administrator views the DNS configuration of an affected domain, the payload executes automatically — enabling complete admin account takeover, credential theft, and full server compromise.</p>
<p>---</p>
<p>### Details</p>
<p>Three code locations combine to create this vulnerability:</p>
<p>**1. Input validation does not strip HTML special characters** — `lib/Froxlor/Api/Commands/DomainZones.php:158`</p>
<p>```php
// Only strips non-printable chars. &lt; and &gt; (0x3C/0x3E) pass through unmodified.
$content = preg_replace('/[^\x09\x20-\x7E]/', '', $content);
$content = Dns::encloseTXTContent($content);  // only wraps in quotes, no HTML encoding
```</p>
<p>**2. Display callback returns raw HTML without escaping** — `lib/Froxlor/UI/Callbacks/Text.php:95`</p>
<p>```php
public static function wordwrap(array $attributes): string {
    return wordwrap($attributes['data'], 100, '&lt;br&gt;', true);  // no htmlspecialchars()
}
```</p>
<p>**3. Twig template renders the callback output with `|raw`** — `templates/Froxlor/table/table.html.twig:57`</p>
<p>```twig
{% else %}
    {{ td.data|raw }}   {# string from wordwrap() — rendered without escaping #}
{% endif %}
```</p>
<p>The DNS editor table assigns `[Text::class, 'wordwrap']` as the callback for the `content` column (`lib/tablelisting/tablelisting.dns.php:58`). The cal…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-43gm-9rr3-cx7g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2113</id>
    <title>WID-SEC-W-2026-2113 — Froxlor: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:02:24.426639+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Froxlor ausnutzen, um Cross-Site-Scripting- oder SQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2113"/>
  </entry>
</feed>
