CRLF Injection Vulnerability in Froxlor Server Administration Panel
CVE-2026-100717
What is CVE-2026-100717?
The Froxlor server administration panel contains a CRLF injection vulnerability in versions 2.3.10 and earlier. The vulnerability arises from the Validate::validateUrl function, which improperly rejects carriage return and line feed characters only in specific components of the URL, neglecting the userinfo part. An authenticated low-privileged user with rights to create subdomains can exploit this by providing a malicious redirect URL with CR/LF payloads in the userinfo segment. This unsanitized input could potentially escape the configuration directives and inject arbitrary web server configurations, posing significant risks such as response hijacking or unauthorized file access. The issue has been addressed in version 2.3.12.
Affected Version(s)
froxlor 0 < 2.3.12
froxlor 2.3.12
