<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:05:53.463100+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-356528</id>
    <title>EUVD-2026-356528</title>
    <updated>2026-10-03T08:05:53.466460+00:00</updated>
    <content>EUVD-2026-356528</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-356528"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54348</id>
    <title>fkie_cve-2026-54348</title>
    <updated>2026-10-03T08:05:53.466491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enforcing numeric element types. When the poisoned account later calls IpsAndPorts.listing, lib/Froxlor/Api/Commands/IpsAndPorts.php decodes the array and concatenates its elements into a SQL IN clause without casting or parameterization; the same unsafe pattern is present in lib/Froxlor/Api/Commands/Domains.php. An authenticated administrator with change_serversettings permission can store a UNION-based payload and trigger it through the poisoned account to retrieve arbitrary database data, including administrator login names and bcrypt password hashes, with potential privilege escalation and broader database impact. This issue is fixed in version 2.3.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w27m-rmmf-g5w4</id>
    <title>GHSA-w27m-rmmf-g5w4 — Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration</title>
    <updated>2026-10-03T08:05:53.466526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: froxlor/froxlor</p>
<p>### Summary</p>
<p>A second-order SQL injection vulnerability in Froxlor's admin API allows an authenticated administrator to store a crafted SQL payload in the `panel_admins.ip` column via the `Admins.add` or `Admins.update` endpoint. The payload executes as a UNION-based SQL injection the next time `IpsAndPorts.listing` is called by the poisoned account, returning arbitrary data from the database — including all administrator login names and bcrypt password hashes.</p>
<p>---</p>
<p>### Details</p>
<p>The vulnerability spans two code locations that form a store-then-trigger chain.</p>
<p>**Stage 1 — Unsanitized array stored as JSON** — `lib/Froxlor/Api/Commands/Admins.php:251,358`</p>
<p>```php
$ipaddress = $this-&gt;getParam('ipaddress', true, -1);
// No type enforcement or content validation on $ipaddress.
// PHP evaluates (is_array([...]) &amp;&amp; non_empty_array &gt; 0) as true,
// so any attacker-controlled array is JSON-encoded and stored verbatim.
'ip' =&gt; empty($ipaddress) ? "" : (is_array($ipaddress) &amp;&amp; $ipaddress &gt; 0
    ? json_encode($ipaddress)   // ← attacker payload written to panel_admins.ip
    : -1),
```</p>
<p>The INSERT/UPDATE uses a prepared statement, so the write itself is safe. The danger is what is stored.</p>
<p>**Stage 2 — JSON payload imploded directly into SQL** — `lib/Froxlor/Api/Commands/IpsAndPorts.php:71-77`</p>
<p>```php
if (!empty($this-&gt;getUserDetail('ip')) &amp;&amp; $this-&gt;getUserDetail('ip') != -1) {
    // json_decode restores the array; implode joins elements with no casting or escaping
    $ip_where = "WHE…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w27m-rmmf-g5w4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2113</id>
    <title>WID-SEC-W-2026-2113 — Froxlor: Mehrere Schwachstellen</title>
    <updated>2026-10-03T08:05:53.466598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Froxlor ausnutzen, um Cross-Site-Scripting- oder SQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2113"/>
  </entry>
</feed>
