Junglewise Threat Intelligence

CVE-2026-100712: froxlor two-factor authentication disable via CSRF GET request

CVE-2026-100712 · Severity: medium · CVSS 6.5 · Published 2026-09-26

Technologies: Froxlor. Vendors: Froxlor.

Executive brief

froxlor is a web hosting control panel that allows administrators and customers to manage their accounts and services. An attacker can disable a logged-in user's two-factor authentication by tricking them into following a malicious link, reducing the account to password-only protection. If the attacker also obtains the victim's password, they gain full account takeover including the ability to mint API keys for persistent access.

Technical details

The vulnerability is a cross-site request forgery (CSRF) affecting the 2FA management endpoint (2fa.php action=delete) which processes state-changing GET requests without CSRF token validation. The global CSRF middleware only guards POST/PUT/PATCH/DELETE methods, leaving GET mutations unprotected, and the session cookie is set to SameSite=Lax, allowing the victim's authenticated session to be carried in cross-site top-level navigation. Both customer and admin 2FA handlers are vulnerable; exploitation requires only luring an authenticated user to click a link, resulting in the immediate nullification of their TOTP enrollment.

Affected products

  • froxlor froxlor through 2.3.10

Timeline

  • 2026-09-26: disclosed: Advisory published
  • 2026-09-06: patched: Fix released in version 2.3.12

References

Related threats