Credential Disclosure Vulnerability in Froxlor by Froxlor
CVE-2026-100719
7.1HIGH
What is CVE-2026-100719?
Froxlor versions prior to 2.3.12 are susceptible to a credential disclosure vulnerability within the DirProtections.listing API command. This issue allows authenticated API users to access bcrypt password hashes for users of protected directories. Such exposure compromises the security of user credentials, enabling potential offline cracking attempts and raising concerns over reused passwords. It is essential for users to upgrade to the latest version to mitigate this risk and safeguard their sensitive information.
Affected Version(s)
froxlor 0 < 2.3.12
froxlor 2.3.12
