THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-43gm-9rr3-cx7g (high) — Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover

[GHSA] GHSA-43gm-9rr3-cx7g (high) — Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover

highgithub_advisoriesPublished 2026-08-18

GHSA-43gm-9rr3-cx7g Severity: high CVE: CVE-2026-54347

Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover

### Summary

A stored Cross-Site Scripting (XSS) vulnerability in Froxlor's DNS editor allows an authenticated user with DNS editor access (customer role) to inject arbitrary JavaScript into any administrator's browser session. When an administrator views

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-43gm-9rr3-cx7g