CyberRota Analysis
AI-GeneratedFroxlor versions up to 2.3.10 are vulnerable due to improper handling of remembered-2FA tokens, which only store numeric user IDs without differentiating between customer and administrator namespaces. This flaw allows an attacker with a customer account that shares an ID with an administrator to bypass the second-factor authentication if they possess a valid remembered-2FA cookie and know the administrator's password. Organizations using affected versions should prioritize upgrading to 2.3.12 to mitigate the risk of unauthorized administrative access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and administrator IDs are allocated from separate namespaces, a remembered-2FA token legitimately issued to a customer with a given ID also matches an administrator with the same ID. An attacker who controls a customer account with a colliding ID, holds a valid remembered-2FA cookie for it, and already knows the target administrator's password can bypass the administrator's TOTP second factor and obtain an authenticated administrator session. This is a second-factor bypass only; it does not defeat password authentication. Fixed in 2.3.12.