CVE-2026-30932

Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. $INCLUDE) into the zone file that gets written to disk when the DNS rebuild cron job runs. This issue has been patched in version 2.3.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:33

Type Values Removed Values Added
Summary
  • (es) Froxlor es un software de administración de servidor de código abierto. Antes de la versión 2.3.5, el endpoint de la API DomainZones.add (accesible para clientes con DNS habilitado) no valida el campo de contenido para varios tipos de registros DNS (LOC, RP, SSHFP, TLSA). Un atacante puede inyectar saltos de línea y directivas de archivo de zona BIND (p. ej., $INCLUDE) en el archivo de zona que se escribe en el disco cuando se ejecuta la tarea cron de reconstrucción de DNS. Este problema ha sido parcheado en la versión 2.3.5.

26 Mar 2026, 12:17

Type Values Removed Values Added
First Time Froxlor
Froxlor froxlor
CPE cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*
References () https://github.com/froxlor/froxlor/commit/b34829262dc32818b37f6a1eabb426d0b277a86b - () https://github.com/froxlor/froxlor/commit/b34829262dc32818b37f6a1eabb426d0b277a86b - Patch
References () https://github.com/froxlor/froxlor/releases/tag/2.3.5 - () https://github.com/froxlor/froxlor/releases/tag/2.3.5 - Product, Release Notes
References () https://github.com/froxlor/froxlor/security/advisories/GHSA-x6w6-2xwp-3jh6 - () https://github.com/froxlor/froxlor/security/advisories/GHSA-x6w6-2xwp-3jh6 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

24 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 19:16

Updated : 2026-06-17 10:33


NVD link : CVE-2026-30932

Mitre link : CVE-2026-30932

CVE.ORG link : CVE-2026-30932


JSON object : View

Products Affected

froxlor

  • froxlor
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')