Stored Cross-Site Scripting Vulnerability in Froxlor by Froxlor
CVE-2026-100720
9.3CRITICAL
What is CVE-2026-100720?
Froxlor versions 2.0.0 to 2.3.10 exhibit a stored cross-site scripting vulnerability due to improper handling of SSL certificate issuer information. When a customer uploads an SSL certificate, the issuer's organization value is stored without adequate sanitization and is subsequently rendered in the Froxlor interface using Twig's raw filter. This allows attacker-supplied values to execute as scripts when accessed by an administrator or reseller. This cross-privilege issue can lead to severe consequences, including administrator account takeover, as the admin has control over critical server configurations. The vulnerability is resolved in Froxlor version 2.3.12.
Affected Version(s)
froxlor 2.0.0 < 2.3.12
froxlor 2.3.12
