← Back to search

CVE-2026-100717

9.9 CRITICALpublic exploit available

Published 2026-09-26 · Updated 2026-09-26

AI risk analysis

Summary
This flaw allows an authenticated low-privilege user to inject arbitrary web-server configuration lines by exploiting URL validation in froxlor's subdomain redirect feature.
Exploitability
Exploitation requires an authenticated user with subdomain-create rights and knowledge of the vulnerability. The attack is relatively complex due to the need to craft a specific payload.
Blast radius
If exploited, the attacker can hijack server-wide responses or read local files, leading to significant server compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to froxlor version 2.3.12 or later.
rcewebauth-bypassconfig-injectionserver

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or change_serversettings privilege required) can supply a subdomain redirect URL that carries a CR/LF payload in the userinfo portion (e.g. http://user%0areturn 200 "pwned";%[email protected]/). The value passes validation, survives IDNA encoding, and is written verbatim into the generated nginx or Apache vhost configuration, allowing the attacker to break out of the emitted directive and inject arbitrary web-server configuration lines. froxlor regenerates and reloads the web-server configuration as root, so the injected directives take effect server-wide and can hijack responses or read local files. The issue is fixed in version 2.3.12.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H

Weaknesses

CWE-93

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.