OVERVIEW Froxlor, an open source server administration platform, contains a DNS record injection vulnerability in versions prior to 2.3.6. The DomainZones::add() function fails to validate DNS record types and does not sanitize newline characters in the content field. When uncommon DNS record types such as NAPTR, PTR, or HINFO are submitted, input validation is completely bypassed, allowing embedded newlines to persist through database storage and into BIND zone files. SEVERITY The vulnerability carries a CVSS score of 8.5 (High) with a network attack vector requiring low complexity and low privileges. An authenticated customer can exploit this remotely without user interaction. The primary impact is integrity compromise through injection of arbitrary DNS records and BIND directives including $INCLUDE, $ORIGIN, and $GENERATE, enabling potential DNS hijacking or lateral movement. A secondary availability impact is possible through malformed directives. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog and is listed as inactive on the Hot List. Community attention and exploit code availability are minimal, though the technical simplicity of the attack warrants attention from organizations operating Froxlor instances. Immediate patching to version 2.3.6 or later is recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.6CPE matchmatch criteria | cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.