logo

Froxlor’s CVSS 10 Flaw Turns Config Files into Persistent Backdoors

ID: 8b95e1d9-4af2-58f1-89ec-052f1f45a081

STIX ID: report--8b95e1d9-4af2-58f1-89ec-052f1f45a081

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed two critical Froxlor vulnerabilities: an API validation gap that allows authenticated users to perform path traversal via language settings leading to arbitrary PHP code execution, and improper escaping when writing userdata.inc.php that enables persistent PHP backdoors executed on every request. The report assigns a maximum-severity CVSS 10 to the most severe issue and recommends fixes including adopting the Web UI's strict language validation, properly escaping backslashes and single quotes, using nowdoc syntax for config strings, and adding input validation for sensitive fields.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.