cvedb.io
CVE-2026-30932
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2026-03-24T19:16:51.863 · Last modified 2026-06-17T10:33:10.477

Summary

Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. $INCLUDE) into the zone file that gets written to disk when the DNS rebuild cron job runs. This issue has been patched in version 2.3.5.

Affected products

froxlor — froxlor

Does this affect you?

Add your gear to cvedb and we'll alert you only when froxlor ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.