Stored Cross-Site Scripting Vulnerability in Froxlor by Froxlor
CVE-2026-100720

9.3CRITICAL

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100720?

Froxlor versions 2.0.0 to 2.3.10 exhibit a stored cross-site scripting vulnerability due to improper handling of SSL certificate issuer information. When a customer uploads an SSL certificate, the issuer's organization value is stored without adequate sanitization and is subsequently rendered in the Froxlor interface using Twig's raw filter. This allows attacker-supplied values to execute as scripts when accessed by an administrator or reseller. This cross-privilege issue can lead to severe consequences, including administrator account takeover, as the admin has control over critical server configurations. The vulnerability is resolved in Froxlor version 2.3.12.

Affected Version(s)

froxlor 2.0.0 < 2.3.12

froxlor 2.3.12

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EvidentObscurity
.