{"id":"CVE-2026-100720","summary":"Froxlor before 2.3.12 Stored XSS via SSL certificate issuer","details":"Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits scalar cells through Twig's `raw` filter, disabling HTML auto-escaping, so when an administrator or reseller opens Domains \u003e SSL certificates the attacker-supplied issuer value executes as script in the privileged user's session. This crosses a privilege boundary from customer to admin and can result in full administrator account takeover; because a Froxlor admin controls webserver, DNS, and PHP configuration applied by a cron job running as root, the issue can be further escalated to command execution as root on the managed server. The issue is fixed in Froxlor 2.3.12.","aliases":["GHSA-89vj-gqqr-73p8"],"modified":"2026-09-28T03:48:30.817784597Z","published":"2026-09-26T13:24:10.569Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100720.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100720.json"},{"type":"ADVISORY","url":"https://github.com/froxlor/froxlor/security/advisories/GHSA-89vj-gqqr-73p8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100720"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/froxlor-before-2.3.12-stored-xss-via-ssl-certificate-issuer"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/froxlor/froxlor","events":[{"introduced":"c400f129c4418ef85794ef39c92815cc34d2d937"},{"fixed":"143b6ee634a4b9c237437b4b1206c7b733b86d95"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.3.12"},{"fixed":"2.3.10"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100720.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"}]}