THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7788-ghfq-c6mh (critical) — Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints

[GHSA] GHSA-7788-ghfq-c6mh (critical) — Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints

medgithub_advisoriesPublished 2026-08-18

GHSA-7788-ghfq-c6mh Severity: critical CVE: CVE-2026-62988

Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints

## Summary

Several Froxlor API command classes return sensitive authentication material in JSON API responses. The affected endpoints retrieve full database rows using `SELECT *`, `SELECT alias.*`, or equivalent full-row queries, then return the results directly thr

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7788-ghfq-c6mh