Back

CRITICAL

Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution

Published Apr 23, 2026

Description

Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set `def_language` to a path traversal payload (e.g., `../../../../../var/customers/webs/customer1/evil`), which is stored in the database. On subsequent requests, `Language::loadLanguage()` constructs a file path using this value and executes it via `require`, achieving arbitrary PHP code execution as the web server user. Version 2.3.6 fixes the issue.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 23, 2026
Updated Apr 23, 2026
Reserved Apr 18, 2026
CISA Vulnrichment
Updated Apr 23, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Apr 23, 2026
Updated Apr 23, 2026
Exploited since n/a
EUVD-2026-25176 GHSA-W59F-67XM-RXX7