Executive brief
Froxlor is a web-based server administration panel used to manage hosting and mail services. A flaw in how it validates SSH public keys allows customers with valid access to inject arbitrary lines into SSH authorized_keys files, potentially creating persistent backdoors that survive key deletions and access revocation. This could allow attackers to maintain unauthorized remote access to server accounts.
Technical details
Froxlor before version 2.3.12 fails to properly validate multi-line SSH public keys submitted via the SshKeys::add() API endpoint. The vulnerability is a line injection flaw where attackers with valid customer account access can include newline characters and option directives in SSH key submissions to inject malicious entries into authorized_keys files. By embedding SSH key options (such as command restrictions or forced command execution), attackers can establish persistent access that persists even after the original key is deleted or SSH access is administratively revoked. The fix is available in version 2.3.12 or later.
Affected products
- Froxlor Froxlor before 2.3.12
Timeline
- 2026-09-13: disclosed