Executive brief
froxlor is a server administration panel that manages web server configurations for hosting providers and resellers. A low-privilege customer with subdomain management rights can inject newline characters into server configuration files via a malicious subdomain redirect URL, allowing them to inject arbitrary nginx or Apache directives that take effect server-wide. This enables attackers to hijack web responses, read local files, or disable services on the server.
Technical details
The Validate::validateUrl function checks only the path, query, and fragment URL components for CRLF sequences but fails to inspect the userinfo (user:pass@) component returned by parse_url. An attacker supplies a subdomain redirect URL with newline characters encoded in the userinfo portion (e.g., http://user%0amalicious%0a@evil.com/), which passes validation and is written verbatim into the generated vhost configuration. When froxlor regenerates and reloads web server config as root, the injected directives execute with full privilege.
Affected products
- froxlor froxlor 2.3.10 and earlier
Timeline
- 2026-09-26: disclosed: Published as GHSA-gxx3-hwjc-h2gp
- 2026-09-26: patched: Fixed in version 2.3.12