DNS Manipulation Vulnerability in Froxlor Open Source Server Administration Software
CVE-2026-54543
5.4MEDIUM
What is CVE-2026-54543?
Froxlor, an open-source server administration tool, contains a vulnerability in its DomainZones.add API command prior to version 2.3.8. This issue arises due to insufficient validation of user-controlled record and type values, allowing authenticated customers with DNS-zone permissions to inject crafted values. The inadequately handled inputs can lead to the creation of unauthorized resource-record lines in the BIND zone file. As a result, this can manipulate DNS data and potentially affect availability within a managed zone, posing significant risks to users and services relying on Froxlor for server management.
Affected Version(s)
froxlor < 2.3.8
