Executive brief
Froxlor is an open-source server management panel used to administer web hosting environments, including DNS settings. A vulnerability in how the software handles DNS record entries allows an attacker with limited privileges to inject malicious data into the server's DNS configuration files. This could lead to the creation of unauthorized DNS records, potentially allowing an attacker to redirect web traffic or intercept communications.
Technical details
Froxlor versions up to 2.3.6 are vulnerable to DNS zone file injection due to improper neutralization of special elements (CWE-74). The software concatenates DNS record content directly into Bind9 zone files. While a patch was introduced to validate LOC, RP, SSHFP, and TLSA records, it was incomplete. Specifically, the regular expression for LOC records uses '\s+', which in PHP's PCRE engine matches newlines, allowing an attacker to embed newlines within a record to inject arbitrary DNS entries. Additionally, TLSA records with 'matchingType=0' lack an upper bound on hex data length, and the validators fail to perform proper zone-file escaping on raw input. An authenticated user with permission to manage DNS records can exploit this to corrupt zone files or redirect traffic. The issue is addressed in version 2.3.7.
Affected products
- Froxlor Froxlor <= 2.3.6
Timeline
- 2026-02-24: patched: Initial fix commit b34829262dc3
- 2026-05-15: advisory: Release of version 2.3.7
- 2026-06-04: disclosed: CVE-2026-41237 published