CyberRota Analysis
AI-GeneratedFroxlor versions up to 2.3.10 are vulnerable due to a failure to enforce the mail.allow_external_domains policy in the EmailSender.add API command, allowing authenticated users to register arbitrary external sender addresses despite administrative restrictions. This vulnerability can lead to sender spoofing, undermining email security and potentially facilitating phishing attacks. Organizations using Froxlor for email management should prioritize updating to version 2.3.12 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external allowed-sender domains (mail.enable_allow_sender = 1, mail.allow_external_domains = 0), an authenticated customer with API access can still use EmailSender.add to register an arbitrary external sender address for their mailbox, which is stored despite the policy. This creates a bypass between the UI/administrator configuration and the API, and — where the generated mail configuration consumes the allowed-sender table — allows a customer to authorize sender identities outside their hosted domains, facilitating sender spoofing. Fixed in 2.3.12.