Impact
Froxlor versions earlier than 2.3.12 accept multi‑line SSH public keys sent to the SshKeys::add() endpoint without proper validation, letting an attacker append arbitrary lines to any user’s authorized_keys file. By inserting SSH option directives, the injected key can remain active even after the original key is removed or the user’s normal SSH access is revoked, allowing a persistent foothold in the system.
Affected Systems
Every installation of Froxlor running any release before 2.3.12 is affected. The vulnerability is fixed only in version 2.3.12 and later.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity, while the EPSS score of < 1% indicates a low baseline probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack requires the ability to reach the SshKeys:: authenticated user with permission to add SSH keys. Once a malicious line is written to a user’s authorized_keys file, it persists through normal key‑management operations, enabling long‑term unauthorized access.
OpenCVE Enrichment