NVD CRITICAL: CVE-2026-100717 — froxlor is a server administration panel. In versions 2.3.10 and earlier, Valida...
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan
CVE-2026-100717