Executive brief
froxlor is a web hosting control panel that allows administrators and customers to manage their accounts and services. An attacker can disable a logged-in user's two-factor authentication by tricking them into following a malicious link, reducing the account to password-only protection. If the attacker also obtains the victim's password, they gain full account takeover including the ability to mint API keys for persistent access.
Technical details
The vulnerability is a cross-site request forgery (CSRF) affecting the 2FA management endpoint (2fa.php action=delete) which processes state-changing GET requests without CSRF token validation. The global CSRF middleware only guards POST/PUT/PATCH/DELETE methods, leaving GET mutations unprotected, and the session cookie is set to SameSite=Lax, allowing the victim's authenticated session to be carried in cross-site top-level navigation. Both customer and admin 2FA handlers are vulnerable; exploitation requires only luring an authenticated user to click a link, resulting in the immediate nullification of their TOTP enrollment.
Affected products
- froxlor froxlor through 2.3.10
Timeline
- 2026-09-26: disclosed: Advisory published
- 2026-09-06: patched: Fix released in version 2.3.12