Executive brief
Froxlor, a web hosting control panel, returns TLS private keys in plaintext through its Certificates API. Low-privileged customer accounts can retrieve private keys for their own domains' certificates, while administrator accounts can extract keys belonging to other customers. Attackers possessing these keys can impersonate the affected domains, decrypt intercepted HTTPS traffic, and launch man-in-the-middle attacks.
Technical details
The Certificates.get and Certificates.listing API commands execute SELECT queries on domain_ssl_settings and pass results directly to the JSON response handler without filtering sensitive columns. The ssl_key_file column, which contains raw PEM-formatted private key content, is returned unmodified. Authentication is required (customer API key or admin credentials) but there is no per-command role-based access control or column-level filtering, allowing authenticated users to enumerate private keys beyond their authorization level.
Affected products
- Froxlor Froxlor before 2.3.13
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: version 2.3.13 released