Skip to main content
Vulnerability Database/CVE-2026-100720

CVE-2026-100720: Froxlor Stored XSS Vulnerability

CVE-2026-100720 is a stored XSS flaw in Froxlor that allows customer-level users to execute malicious scripts in administrator sessions through SSL certificate uploads. This article covers technical details, affected versions, privilege escalation risks, and mitigation steps.

Published:

CVE-2026-100720 Overview

CVE-2026-100720 is a stored cross-site scripting (XSS) vulnerability affecting Froxlor versions 2.0.0 through 2.3.10. A low-privileged customer can upload a crafted SSL certificate whose issuer organization field contains JavaScript. Froxlor stores the parsed issuer['O'] value verbatim and later renders it through Twig's raw filter, bypassing HTML auto-escaping. When an administrator or reseller opens the Domains > SSL certificates view, the attacker-supplied script executes in the privileged session. Because Froxlor admins control webserver, DNS, and PHP configuration applied by a root cron job, the issue can escalate from customer account to root command execution on the managed server.

Critical Impact

Authenticated low-privileged customers can achieve full administrator takeover and, through Froxlor's root cron job, execute arbitrary commands as root on the managed server.

Affected Products

  • Froxlor 2.0.0 through 2.3.10
  • Froxlor Certificates API add() and update() methods
  • Froxlor administrative Domains > SSL certificates view

Discovery Timeline

  • 2026-09-26 - CVE-2026-100720 published to the National Vulnerability Database (NVD)
  • 2026-09-26 - Last updated in NVD database

Technical Details for CVE-2026-100720

Vulnerability Analysis

The vulnerability is a stored cross-site scripting flaw classified under [CWE-79]. It crosses a privilege boundary from the customer role, the lowest-privileged authenticated tier, to administrator and reseller roles. Exploitation requires only that a privileged user open the SSL certificates listing, a routine administrative action.

The payload persists in Froxlor's database as part of the certificate metadata extracted from the uploaded PEM. Any administrator who later views the certificate table triggers execution. From an admin-controlled session, an attacker can modify webserver, DNS, and PHP configuration files that Froxlor writes to disk and that a cron job applies as root, enabling arbitrary command execution with root privileges.

Root Cause

Froxlor's Certificates API parses uploaded X.509 certificates with PHP's openssl_x509_parse() and stores the resulting issuer['O'] string without sanitization or output encoding. The table-listing renderer then emits scalar cell values through Twig's raw filter, which explicitly disables the templating engine's HTML auto-escape protections. The combination of unsanitized input and unescaped output produces a persistent XSS sink.

Attack Vector

An authenticated customer generates a self-signed certificate whose issuer organization (O=) attribute contains an HTML <script> payload. The attacker uploads this certificate for one of their own domains through the standard Froxlor customer workflow. When an administrator or reseller browses to Domains > SSL certificates, the browser parses the payload as HTML and executes the script in the privileged user's session, enabling session hijacking, forced configuration changes, or privilege escalation to root through Froxlor's root cron job.

Technical details are documented in the GitHub Security Advisory GHSA-89vj-gqqr-73p8 and the VulnCheck Froxlor XSS Advisory.

Detection Methods for CVE-2026-100720

Indicators of Compromise

  • SSL certificates stored in Froxlor whose issuer['O'] field contains HTML tags, angle brackets, or JavaScript event handlers such as onerror= and onload=.
  • Unexpected administrator or reseller session activity shortly after a customer uploads a new SSL certificate.
  • Modifications to webserver, DNS, or PHP configuration files generated by Froxlor that do not correspond to legitimate administrative actions.

Detection Strategies

  • Query the Froxlor database for panel_certificates rows where the stored issuer fields contain <, >, or script substrings.
  • Review web server access logs for POST requests to the Froxlor Certificates API endpoints followed by administrator GETs to the SSL certificates listing.
  • Audit root cron job output and generated configuration diffs for unexpected shell command insertion.

Monitoring Recommendations

  • Alert on changes to Froxlor-managed files written outside normal administrative workflows.
  • Monitor privileged session creation and API calls originating from administrator accounts immediately after certificate upload events by customer accounts.
  • Capture browser-side errors or Content Security Policy (CSP) violations from the Froxlor administrative UI, which can indicate attempted script execution.

How to Mitigate CVE-2026-100720

Immediate Actions Required

  • Upgrade Froxlor to version 2.3.12 or later on all managed hosts.
  • Review existing certificates in the panel and remove any whose issuer fields contain HTML or script content before administrators access the SSL certificates view.
  • Rotate administrator and reseller credentials and invalidate active sessions if exploitation is suspected.

Patch Information

The issue is fixed in Froxlor 2.3.12. See the GitHub Security Advisory GHSA-89vj-gqqr-73p8 for the upstream fix and release notes.

Workarounds

  • Temporarily disable customer-facing SSL certificate upload functionality until the patch is applied.
  • Restrict customer accounts from managing SSL certificates through role or permission adjustments where feasible.
  • Deploy a strict Content Security Policy on the Froxlor administrative interface to limit inline script execution as a defense-in-depth measure.
bash
# Upgrade Froxlor to the fixed release on Debian/Ubuntu
sudo apt update
sudo apt install --only-upgrade froxlor
froxlor-cli --version   # verify version >= 2.3.12

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.