Impact
Froxlor versions earlier than 2.3.7 allow an authenticated attacker to find global sender alias IDs by sending arbitrary senderid values through customer_email.php. This flaw lets the attacker read other customers' allowed sender values, compromising confidentiality. The weakness originates from improper scoping of alias lookups and is classified as CWE-200.
Affected Systems
The vulnerability affects the Froxlor web hosting control panel. All installations running a version earlier than 2.3.7 are vulnerable. Only authenticated users can exploit the flaw, but they can enumerate and read sender alias data of other users.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium risk. EPSS is not available for this entry, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires valid authentication and the ability to send crafted requests to the customer_email.php endpoint. Successful exploitation results in disclosure of authorized sender addresses for other customers.
OpenCVE Enrichment