CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100717

CRITICALCVSS 9.9NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix f

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100717 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100717

CRITICALCVSS 9.9NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix f

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]