{"apiVersion":"1.0","identifier":"CVE-2026-54347","description":"Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::wordwrap without HTML escaping, and templates/Froxlor/table/table.html.twig renders the callback result with the raw filter. An authenticated customer with DNS editor access can store JavaScript-bearing content in a TXT record. When an administrator views the affected domain-s DNS configuration, the payload executes automatically in the administrator-s browser session, which can expose session data or perform privileged panel actions. This issue is fixed in version 2.3.8.","publishedAt":"2026-08-18T21:16:36","lastModifiedAt":"2026-08-19T19:17:19","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54347","cvssScore":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","epssProbability":0.00382,"riskScore":0.9,"affectedProduct":"Froxlor","affectedVersions":"<2.3.8","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-54347","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-54347","en":"https://www.redsauce.net/en/cves/CVE-2026-54347","fr":"https://www.redsauce.net/fr/cves/CVE-2026-54347","pt":"https://www.redsauce.net/pt/cves/CVE-2026-54347","de":"https://www.redsauce.net/de/cves/CVE-2026-54347","sk":"https://www.redsauce.net/sk/cves/CVE-2026-54347","el":"https://www.redsauce.net/el/cves/CVE-2026-54347"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-54347"}}