Executive brief
Froxlor is a web hosting control panel that manages domains and email configuration. An authenticated admin with delegated cross-tenant visibility can extract DKIM private signing keys—cryptographic secrets used to verify domain ownership—for domains belonging to other administrators. An attacker with these keys can forge emails that appear to come from legitimate domains, bypassing email authentication checks that recipients rely on.
Technical details
The Domains::get(), Domains::listing(), SubDomains::get(), and admin-branch SubDomains::listing() API commands perform an unfiltered wildcard SELECT on the panel_domains table and return all columns including dkim_privkey without sanitization. An authenticated non-superadmin with the customers_see_all delegation flag can call these endpoints to read other tenants' DKIM private keys. The vulnerability is an information disclosure (CWE-200) requiring prior admin authentication; a single listing call can exfiltrate keys for all visible domains.
Affected products
- Froxlor Froxlor through 2.3.10
Timeline
- 2026-09-26: disclosed
- 2026-09-06: patched: Fix released in version 2.3.12