{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/froxlor--2.2.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-90937"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["froxlor (\u003c 2.2.5)"],"_cs_severities":["medium"],"_cs_tags":["web-application-vulnerability","configuration-injection","server-hijacking"],"_cs_type":"advisory","_cs_vendors":["Froxlor"],"content_html":"\u003cp\u003eFroxlor versions prior to 2.2.5 fail to perform adequate input validation on subdomain redirect URLs within the administrative interface. An authenticated customer can submit a crafted URL containing literal newline characters (\\n or \\r\\n). When the froxlor cron job triggers a configuration rebuild for the web server, these newline characters are written verbatim into the generated vhost configuration files for Nginx or Apache.\u003c/p\u003e\n\u003cp\u003eThis injection allows an attacker to terminate existing configuration lines and introduce entirely new directives into the web server context. This can lead to the hijacking of HTTP responses across other hosted domains, redirection of traffic to malicious destinations, or denial of service through the injection of syntax errors that prevent web server service restarts. Defenders should prioritize updating to version 2.2.5 or later to enforce proper sanitization of redirect parameters.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the froxlor customer panel.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the subdomain management section.\u003c/li\u003e\n\u003cli\u003eAttacker submits a new or existing subdomain redirect URL containing injected newline characters followed by malicious web server directives (e.g., 'https://site.com\\nrewrite ^/ /malicious_path').\u003c/li\u003e\n\u003cli\u003eThe input is persisted in the backend database without validation.\u003c/li\u003e\n\u003cli\u003eThe server-side cron job executes, invoking the configuration generator script.\u003c/li\u003e\n\u003cli\u003eThe script retrieves the malicious input and writes it to the active Nginx or Apache vhost configuration file.\u003c/li\u003e\n\u003cli\u003eThe system reloads the web server configuration to apply changes.\u003c/li\u003e\n\u003cli\u003eWeb server processes the injected directives, leading to hijacking or service disruption.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated user to perform service-wide configuration corruption. This enables attackers to hijack HTTP responses for unrelated domains hosted on the same infrastructure, bypass security controls, or cause a denial of service for the entire web server instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Froxlor to version 2.2.5 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview web server configuration files for unexpected directives, particularly those following subdomain definitions.\u003c/li\u003e\n\u003cli\u003eAudit logs for customer panel activity specifically looking for URL inputs containing newline characters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T17:34:27Z","date_published":"2026-09-14T17:34:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-froxlor-config-injection/","summary":"Froxlor versions before 2.2.5 contain a vulnerability allowing authenticated users to inject arbitrary Nginx or Apache configuration directives via unvalidated newline characters in subdomain redirect URLs.","title":"CVE-2026-90937 Configuration Injection in Froxlor","url":"https://feed.craftedsignal.io/briefs/2026-09-froxlor-config-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Froxlor (\u003c 2.2.5)","version":"https://jsonfeed.org/version/1.1"}