<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:03:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-356528</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356528</link>
      <description>EUVD-2026-356528</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356528</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54348</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54348</link>
      <description>&lt;p&gt;Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enforcing numeric element types. When the poisoned account later calls IpsAndPorts.listing, lib/Froxlor/Api/Commands/IpsAndPorts.php decodes the array and concatenates its elements into a SQL IN clause without casting or parameterization; the same unsafe pattern is present in lib/Froxlor/Api/Commands/Domains.php. An authenticated administrator with change_serversettings permission can store a UNION-based payload and trigger it through the poisoned account to retrieve arbitrary database data, including administrator login names and bcrypt password hashes, with potential privilege escalation and broader database impact. This issue is fixed in version 2.3.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enforcing numeric element types. When the poisoned account later calls IpsAndPorts.listing, lib/Froxlor/Api/Commands/IpsAndPorts.php decodes the array and concatenates its elements into a SQL IN clause without casting or parameterization; the same unsafe pattern is present in lib/Froxlor/Api/Commands/Domains.php. An authenticated administrator with change_serversettings permission can store a UNION-based payload and trigger it through the poisoned account to retrieve arbitrary database data, including administrator login names and bcrypt password hashes, with potential privilege escalation and broader database impact. This issue is fixed in version 2.3.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54348</guid>
    </item>
    <item>
      <title>GHSA-w27m-rmmf-g5w4 — Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w27m-rmmf-g5w4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A second-order SQL injection vulnerability in Froxlor&amp;#39;s admin API allows an authenticated administrator to store a crafted SQL payload in the `panel_admins.ip` column via the `Admins.add` or `Admins.update` endpoint. The payload executes as a UNION-based SQL injection the next time `IpsAndPorts.listing` is called by the poisoned account, returning arbitrary data from the database — including all administrator login names and bcrypt password hashes.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability spans two code locations that form a store-then-trigger chain.&lt;/p&gt;
&lt;p&gt;**Stage 1 — Unsanitized array stored as JSON** — `lib/Froxlor/Api/Commands/Admins.php:251,358`&lt;/p&gt;
&lt;p&gt;```php
$ipaddress = $this-&amp;gt;getParam(&amp;#39;ipaddress&amp;#39;, true, -1);
// No type enforcement or content validation on $ipaddress.
// PHP evaluates (is_array([...]) &amp;amp;&amp;amp; non_empty_array &amp;gt; 0) as true,
// so any attacker-controlled array is JSON-encoded and stored verbatim.
&amp;#39;ip&amp;#39; =&amp;gt; empty($ipaddress) ? &amp;#34;&amp;#34; : (is_array($ipaddress) &amp;amp;&amp;amp; $ipaddress &amp;gt; 0
    ? json_encode($ipaddress)   // ← attacker payload written to panel_admins.ip
    : -1),
```&lt;/p&gt;
&lt;p&gt;The INSERT/UPDATE uses a prepared statement, so the write itself is safe. The danger is what is stored.&lt;/p&gt;
&lt;p&gt;**Stage 2 — JSON payload imploded directly into SQL** — `lib/Froxlor/Api/Commands/IpsAndPorts.php:71-77`&lt;/p&gt;
&lt;p&gt;```php
if (!empty($this-&amp;gt;getUserDetail(&amp;#39;ip&amp;#39;)) &amp;amp;&amp;amp; $this-&amp;gt;getUserDetail(&amp;#39;ip&amp;#39;) != -1) {
    // json_decode restores the array; implode joins elements with no casting or escaping
    $ip_where = &amp;#34;WHE…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A second-order SQL injection vulnerability in Froxlor&amp;#39;s admin API allows an authenticated administrator to store a crafted SQL payload in the `panel_admins.ip` column via the `Admins.add` or `Admins.update` endpoint. The payload executes as a UNION-based SQL injection the next time `IpsAndPorts.listing` is called by the poisoned account, returning arbitrary data from the database — including all administrator login names and bcrypt password hashes.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability spans two code locations that form a store-then-trigger chain.&lt;/p&gt;
&lt;p&gt;**Stage 1 — Unsanitized array stored as JSON** — `lib/Froxlor/Api/Commands/Admins.php:251,358`&lt;/p&gt;
&lt;p&gt;```php
$ipaddress = $this-&amp;gt;getParam(&amp;#39;ipaddress&amp;#39;, true, -1);
// No type enforcement or content validation on $ipaddress.
// PHP evaluates (is_array([...]) &amp;amp;&amp;amp; non_empty_array &amp;gt; 0) as true,
// so any attacker-controlled array is JSON-encoded and stored verbatim.
&amp;#39;ip&amp;#39; =&amp;gt; empty($ipaddress) ? &amp;#34;&amp;#34; : (is_array($ipaddress) &amp;amp;&amp;amp; $ipaddress &amp;gt; 0
    ? json_encode($ipaddress)   // ← attacker payload written to panel_admins.ip
    : -1),
```&lt;/p&gt;
&lt;p&gt;The INSERT/UPDATE uses a prepared statement, so the write itself is safe. The danger is what is stored.&lt;/p&gt;
&lt;p&gt;**Stage 2 — JSON payload imploded directly into SQL** — `lib/Froxlor/Api/Commands/IpsAndPorts.php:71-77`&lt;/p&gt;
&lt;p&gt;```php
if (!empty($this-&amp;gt;getUserDetail(&amp;#39;ip&amp;#39;)) &amp;amp;&amp;amp; $this-&amp;gt;getUserDetail(&amp;#39;ip&amp;#39;) != -1) {
    // json_decode restores the array; implode joins elements with no casting or escaping
    $ip_where = &amp;#34;WHE…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w27m-rmmf-g5w4</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2113 — Froxlor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2113</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Froxlor ausnutzen, um Cross-Site-Scripting- oder SQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Froxlor ausnutzen, um Cross-Site-Scripting- oder SQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2113</guid>
    </item>
  </channel>
</rss>
