CRLF Injection Vulnerability in Froxlor Server Administration Panel
CVE-2026-100717

8.5HIGH

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100717?

The Froxlor server administration panel contains a CRLF injection vulnerability in versions 2.3.10 and earlier. The vulnerability arises from the Validate::validateUrl function, which improperly rejects carriage return and line feed characters only in specific components of the URL, neglecting the userinfo part. An authenticated low-privileged user with rights to create subdomains can exploit this by providing a malicious redirect URL with CR/LF payloads in the userinfo segment. This unsanitized input could potentially escape the configuration directives and inject arbitrary web server configurations, posing significant risks such as response hijacking or unauthorized file access. The issue has been addressed in version 2.3.12.

Affected Version(s)

froxlor 0 < 2.3.12

froxlor 2.3.12

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
.