<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:10:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355416</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355416</link>
      <description>EUVD-2026-355416</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355416</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54543</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54543</link>
      <description>&lt;p&gt;Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab characters, semicolons, or unsupported DNS record types before lib/Froxlor/Dns/DnsEntry.php serializes the values into a BIND zone file. An authenticated customer with DNS-zone permissions can place a crafted value in the record field, or use the related type-field variant, to create additional resource-record lines that bypass Froxlor&amp;#39;s field-level validation. BIND accepts the injected records, allowing modification of DNS data and possible DNS availability impact within a zone the caller is authorized to manage. This issue is fixed in version 2.3.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab characters, semicolons, or unsupported DNS record types before lib/Froxlor/Dns/DnsEntry.php serializes the values into a BIND zone file. An authenticated customer with DNS-zone permissions can place a crafted value in the record field, or use the related type-field variant, to create additional resource-record lines that bypass Froxlor&amp;#39;s field-level validation. BIND accepts the injected records, allowing modification of DNS data and possible DNS availability impact within a zone the caller is authorized to manage. This issue is fixed in version 2.3.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54543</guid>
    </item>
    <item>
      <title>GHSA-5rw4-4665-cvwf — Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5rw4-4665-cvwf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;Froxlor&amp;#39;s DomainZones.add API command accepts user-controlled DNS record and type values and later writes them into generated BIND zone files without rejecting line delimiters, tab characters, or zone-file comment delimiters.&lt;/p&gt;
&lt;p&gt;The stronger variant is in record. An authenticated customer with DNS-zone permissions can submit a normal A record request where record is:&lt;/p&gt;
&lt;p&gt;www\t60\tIN\tA\t6.6.6.6 ;\n@&lt;/p&gt;
&lt;p&gt;with type=A and content=127.0.0.1. The current record flow trims/lower-cases/IDNA-encodes the value, but does not reject CR/LF/HTAB or semicolon. The real Froxlor\Dns\DnsEntry::__toString() sink renders it as:&lt;/p&gt;
&lt;p&gt;www    60    in    a    6.6.6.6 ;
@      18000 IN    A    127.0.0.1&lt;/p&gt;
&lt;p&gt;BIND accepts the generated zone file:&lt;/p&gt;
&lt;p&gt;named-checkzone example.com froxlor_dns_record_injected.zone
zone example.com/IN: loaded serial 2026060501
OK&lt;/p&gt;
&lt;p&gt;named-compilezone -D confirms both records are parsed as real DNS RRs:&lt;/p&gt;
&lt;p&gt;example.com.       18000 IN A 127.0.0.1
www.example.com.      60 IN A 6.6.6.6
zone example.com/IN: loaded serial 2026060501
OK&lt;/p&gt;
&lt;p&gt;Affected code in 2.3.7:
- lib/Froxlor/Api/Commands/DomainZones.php:92-93 reads record/type from API params.
- lib/Froxlor/Api/Commands/DomainZones.php:122-136 trims/lower-cases/IDNA-encodes record without control-character rejection.
- lib/Froxlor/Api/Commands/DomainZones.php:157-160 hardens content only.
- lib/Froxlor/Api/Commands/DomainZones.php:314-321 and 347-357 store record/type/content into domain_dns_entries.
- lib/Froxlor/Dns/Dns.php:297 passes stored value…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;Froxlor&amp;#39;s DomainZones.add API command accepts user-controlled DNS record and type values and later writes them into generated BIND zone files without rejecting line delimiters, tab characters, or zone-file comment delimiters.&lt;/p&gt;
&lt;p&gt;The stronger variant is in record. An authenticated customer with DNS-zone permissions can submit a normal A record request where record is:&lt;/p&gt;
&lt;p&gt;www\t60\tIN\tA\t6.6.6.6 ;\n@&lt;/p&gt;
&lt;p&gt;with type=A and content=127.0.0.1. The current record flow trims/lower-cases/IDNA-encodes the value, but does not reject CR/LF/HTAB or semicolon. The real Froxlor\Dns\DnsEntry::__toString() sink renders it as:&lt;/p&gt;
&lt;p&gt;www    60    in    a    6.6.6.6 ;
@      18000 IN    A    127.0.0.1&lt;/p&gt;
&lt;p&gt;BIND accepts the generated zone file:&lt;/p&gt;
&lt;p&gt;named-checkzone example.com froxlor_dns_record_injected.zone
zone example.com/IN: loaded serial 2026060501
OK&lt;/p&gt;
&lt;p&gt;named-compilezone -D confirms both records are parsed as real DNS RRs:&lt;/p&gt;
&lt;p&gt;example.com.       18000 IN A 127.0.0.1
www.example.com.      60 IN A 6.6.6.6
zone example.com/IN: loaded serial 2026060501
OK&lt;/p&gt;
&lt;p&gt;Affected code in 2.3.7:
- lib/Froxlor/Api/Commands/DomainZones.php:92-93 reads record/type from API params.
- lib/Froxlor/Api/Commands/DomainZones.php:122-136 trims/lower-cases/IDNA-encodes record without control-character rejection.
- lib/Froxlor/Api/Commands/DomainZones.php:157-160 hardens content only.
- lib/Froxlor/Api/Commands/DomainZones.php:314-321 and 347-357 store record/type/content into domain_dns_entries.
- lib/Froxlor/Dns/Dns.php:297 passes stored value…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5rw4-4665-cvwf</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2113 — Froxlor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2113</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Froxlor ausnutzen, um Cross-Site-Scripting- oder SQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Froxlor ausnutzen, um Cross-Site-Scripting- oder SQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2113</guid>
    </item>
  </channel>
</rss>
