External risk intelligence

Froxlor Stored XSS via SSL Certificate Issuer.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-100720

Froxlor is a server management panel commonly deployed as a public-facing web interface for hosting administration. While the vulnerability requires authentication, the nature of the software as a web-based hosting control panel means it is frequently accessed over the internet, and the administrative interface is a common target reachable via the web.

Cross-site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability in Froxlor, a web-based server management tool, allows a lower-privileged user to potentially gain full administrative control. This could escalate to command execution on the server, impacting the integrity of managed hosting and DNS configurations.

  • Stored cross-site scripting allows lower-privileged users to execute code.
  • It can lead to full administrator account takeover.
  • Confirm if Froxlor is in use and assess potential impact.

Attack Path

How an attacker could exploit the issue

An attacker with a customer account could upload a specially crafted SSL certificate for one of their domains. The Froxlor system processes this certificate and stores a specific piece of data from it without proper cleaning. When a more privileged user, such as an administrator or reseller, later views a list of SSL certificates, the uncleaned data is displayed in a way that allows malicious script to run within their browser session, potentially leading to full control of the server.

  • Authenticated customer account needed.
  • Malicious SSL certificate upload.
  • Admin account takeover and server compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact sensitive information and administrative control within Froxlor. When a customer uploads an SSL certificate, a specific value from the certificate's issuer is stored without proper sanitization. If an administrator or reseller views the list of SSL certificates, this unsanitized data can execute as script within their privileged session, potentially leading to full administrator account takeover. This could escalate to command execution as root on the server because Froxlor administrators manage critical server configurations.

  • Administrator session data at risk.
  • An attacker exploits stored certificate data.
  • Could lead to root command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Froxlor platform's ownership likely spans application, infrastructure, and security teams. The initial step is to locate all Froxlor instances, determine their reachability and business criticality, identify the accountable owner for each instance, and then plan remediation based on the assessed risk.

  • Identify Froxlor instances and owners.
  • Verify certificate API exposure and reachability.
  • Plan risk-based remediation or upgrade.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Froxlor and what is it used for?

Froxlor is an open-source server management panel designed to simplify web hosting administration. It provides a web-based interface for customers and administrators to manage domains, SSL certificates, email accounts, and database settings. Because it automates complex tasks like configuring web servers and DNS via root-level cron jobs, it acts as a central control hub for the entire managed hosting environment.

How does CVE-2026-100720 result in a security compromise?

This vulnerability is a Stored Cross-Site Scripting (XSS) weakness classified as CWE-79. It occurs because the software saves specific data from an uploaded SSL certificate without cleaning it. When a privileged administrator views the certificate list, the application displays this stored data directly in the browser. This allows the saved content to execute as malicious code, potentially hijacking the admin session to gain full control of the platform.

Can any user trigger this vulnerability?

No, this cannot be triggered by an anonymous visitor. A successful attack requires a pre-existing, authenticated customer account on the Froxlor system. The attacker must possess the privileges necessary to upload an SSL certificate for a domain they manage. Simply browsing the site or attempting to access the admin interface without these specific user-level permissions will not initiate the flaw.

Is my Froxlor instance at risk?

Halo Surface Signal indicates that Froxlor is frequently deployed as a public-facing web interface, making it a common target for external access. If your management panel is reachable via the internet, your administrative interface is likely exposed. Because this bug allows an attacker to escalate from a low-privileged customer role to full administrator, any internet-facing installation should be treated as high priority.

What should I do first to address this threat?

Begin by auditing your infrastructure to locate all active Froxlor instances and identify the team responsible for each. Once your inventory is complete, prioritize upgrading to version 2.3.12 or later, which contains the necessary security fixes. While preparing for the update, review logs for suspicious certificate upload activity by customer accounts.

References