Executive brief
Froxlor is a web hosting control panel that manages customer and administrator accounts. An attacker who knows an administrator's password and controls a customer account with a matching numeric ID can bypass the administrator's two-factor authentication (TOTP) by reusing the customer's remembered 2FA token, gaining full administrative access to the panel including all customer data and configuration.
Technical details
The panel_2fa_tokens table stores only a numeric user ID without recording whether the token belongs to a customer or administrator account, despite these IDs being allocated from separate namespaces. During login, the remembered-token lookup does not constrain results to the account type being authenticated, allowing a customer token with ID N to satisfy authentication for an administrator with ID N. The vulnerability requires the attacker to already possess both the target administrator's password and a valid remembered 2FA cookie from a customer account with a colliding ID; it is a second-factor bypass that does not defeat password authentication. The vulnerability is fixed in version 2.3.12.
Affected products
- Froxlor Froxlor through 2.3.10
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: fixed in version 2.3.12