What is CVE-2026-54347?
A stored XSS vulnerability was found in Froxlor server administration software below version 2.3.8, caused by insufficient filtering of HTML special characters in DNS TXT record content. This could allow an authenticated user to execute injected JavaScript. Upgrading to version 2.3.8 or later is recommended to mitigate the issue.
Azərbaycanca: Froxlor idarəetmə proqramında DNS TXT qeydlərinin HTML xüsusi simvollarının süzgəcdən keçirilməməsi səbəbindən 2.3.8 versiyasından əvvəlki versiyalarda saxlanılmış XSS (Cross-Site Scripting) zəifliyi aşkarlanıb. Bu zəiflikdən istifadə edərək autentifikasiya olunmuş istifadəçi inyeksiya edilmiş JavaScript-i işə sala bilər. Təsirə məruz qalmamaq üçün Froxlor-u 2.3.8 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which function in Froxlor had insufficient filtering of HTML special characters leading to CVE-2026-54347?
The function managing DNS TXT records in Froxlor had insufficient filtering of HTML special characters.
To which version should Froxlor be upgraded to mitigate CVE-2026-54347?
To mitigate the vulnerability, it is recommended to upgrade Froxlor to version 2.3.8 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.